A likely Russian threat actor is deploying a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices by chaining two vulnerabilities in Cisco's Firewall Management Center (FMC) technology.
In separate reports, Sophos and Cisco identified the malware as a new version of Cyclops Blink, a modular botnet and backdoor that US and UK government agencies have previously linked to Sandworm, a threat actor with ties to Russia's Main Intelligence Directorate (GRU).
Two Separate Cisco FMC Vulnerabilities
Cisco described the Cyclops Blinks activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software. One of the vulnerabilities is CVE-2026-20079, a maximum severity authentication bypass vulnerability that lets an unauthenticated remote attacker run arbitrary code on affected devices and gain root access to the underlying operating system. The second vulnerability, tracked as CVE-2026-20316, is a lower severity flaw with a 5.3 CVSS score that allows a remote attacker to log in with low privileges and then use other previous FMC vulnerabilities to escalate privileges.
Related:Maximum Severity GitLab Flaw Puts Supply Chains at Risk
Threat actors possibly tied to Sandworm are chaining the two flaws to first download a Netcat-based reverse shell and proxy tool on vulnerable FMC systems and then use that to deploy the new Cyclops Blink variant.
Cisco released hotfixes for both bugs last week and "strongly advised" organizations using the affected technology to apply them immediately, citing evidence of exploit activity in the world. The company said it would release a broader, hardened release with fixes for the two new flaws and other internally discovered vulnerabilities in FMC later this week. "Given the in the wild abuse we strongly recommend that customers apply the referenced hotfixes as soon as possible, pending the hardening release," Cisco said.
Cyclops Blink is malware that first surfaced in 2022 and initially targeted WatchGuard firewalls and, later, ASUS devices. Its core functions included beaconing information about infected devices to command-and-control (C2) servers, downloading and executing malicious files, and adding new modules to expand its capabilities.
The malware could persist through reboots and legitimate firmware updates, making it difficult to remove. However, the FBI led a court-authorized operation in which it accessed victims' devices, copied the Cyclops Blink malware, and then removed it.
A Significant Upgrade for Cyclops Blink
... continue reading