<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Detection-Engineering on Juan Carlos Munera</title><link>https://cybersecpro.me/tags/detection-engineering/</link><description>Recent content in Detection-Engineering on Juan Carlos Munera</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Juan Carlos Munera</copyright><lastBuildDate>Tue, 28 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://cybersecpro.me/tags/detection-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>FIRESTARTER and the Detection Gap CISA Just Made Official</title><link>https://cybersecpro.me/posts/firestarter-cisco-backdoor-detection-gap/</link><pubDate>Tue, 28 Apr 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/firestarter-cisco-backdoor-detection-gap/</guid><description>On April 23, 2026, CISA and the UK NCSC published a malware analysis report on FIRESTARTER, a custom backdoor that survives patching, reboots, and firmware upgrades on Cisco Firepower and Secure Firewall devices. The federal directive itself states that Sigma rules are not effective against it. That admission has implications well beyond the federal civilian executive branch.</description></item></channel></rss>