Tech News
← Home  ·  All topics

Qilin Ransomware

3 GoKawiil briefs on this topic

Cisco Talos: Ransomware and state hackers exploit FMC firewall flaws

Cisco Talos reported that three distinct threat groups—including Qilin ransomware affiliates and state-sponsored actors—have been exploiting two vulnerabilities in Cisco Secure Firewall Management Center. The flaws, a maximum-severity authentication bypass (CVE-2026-20079) and a static credential issue (CVE-2026-20316), let attackers gain root access, deploy web shells, steal credentials, and in some cases install Qilin ransomware or Cyclops Blink malware. Cisco has issued hot fixes and urges immediate patching, with broader hardening updates planned next week.

ATF Declares Major Cyber Incident After Qilin Ransomware Claim

The ATF confirmed a cyberattack on a standalone system separate from its main network, formally classifying it as a 'major incident' that requires notifying Congress within a week. An ATF spokesperson said the affected system held sensitive data, including targets of ATF investigations. The Qilin ransomware gang has claimed responsibility on its leak site, though it has not published proof such as stolen data samples.

ATF confirms breach of isolated system after Qilin ransomware claim

The ATF acknowledged that a standalone system separate from its main network was compromised, calling it a 'major incident' after the Qilin ransomware gang listed the agency on its dark web leak site. The agency said the affected system does not connect to its enterprise network or eForms platform, and is now working with the Department of Justice to investigate the breach.