Security researchers at Sophos and Cisco report that a suspected Russian state actor, previously tied to the Sandworm group linked to Russia's GRU, is exploiting two vulnerabilities in Cisco's Secure Firewall Management Center software. The attackers chain a maximum-severity authentication bypass flaw with a lower-severity privilege escalation bug to install a reverse shell and then deploy an updated version of the Cyclops Blink implant, which can steal credentials, map internal networks, and intercept live traffic.
darkreading.com
· 2026-09-14
Cisco Talos reported that three distinct threat groups—including Qilin ransomware affiliates and state-sponsored actors—have been exploiting two vulnerabilities in Cisco Secure Firewall Management Center. The flaws, a maximum-severity authentication bypass (CVE-2026-20079) and a static credential issue (CVE-2026-20316), let attackers gain root access, deploy web shells, steal credentials, and in some cases install Qilin ransomware or Cyclops Blink malware. Cisco has issued hot fixes and urges immediate patching, with broader hardening updates planned next week.
bleepingcomputer.com
· 2026-09-10
Cisco has verified that attackers are actively exploiting CVE-2026-20079, a maximum-severity (CVSS 10.0) flaw in its Secure Firewall Management Center software that lets unauthenticated remote attackers bypass login and run commands as root. The company first disclosed the bug in March without evidence of exploitation, but updated its advisory this week to acknowledge PSIRT detected active attacks in August, though it hasn't shared attacker identity or attack timeline details. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to patch.
bleepingcomputer.com
· 2026-09-09