Tech News
← Home  ·  All topics

Cyclops Blink

2 GoKawiil briefs on this topic

Sandworm exploits two Cisco FMC bugs to deploy new Cyclops Blink malware

Security researchers at Sophos and Cisco report that a suspected Russian state actor, previously tied to the Sandworm group linked to Russia's GRU, is exploiting two vulnerabilities in Cisco's Secure Firewall Management Center software. The attackers chain a maximum-severity authentication bypass flaw with a lower-severity privilege escalation bug to install a reverse shell and then deploy an updated version of the Cyclops Blink implant, which can steal credentials, map internal networks, and intercept live traffic.

Cisco Talos: Ransomware and state hackers exploit FMC firewall flaws

Cisco Talos reported that three distinct threat groups—including Qilin ransomware affiliates and state-sponsored actors—have been exploiting two vulnerabilities in Cisco Secure Firewall Management Center. The flaws, a maximum-severity authentication bypass (CVE-2026-20079) and a static credential issue (CVE-2026-20316), let attackers gain root access, deploy web shells, steal credentials, and in some cases install Qilin ransomware or Cyclops Blink malware. Cisco has issued hot fixes and urges immediate patching, with broader hardening updates planned next week.