Tech News
← Home  ·  All topics

Sandworm

1 GoKawiil brief on this topic

Sandworm exploits two Cisco FMC bugs to deploy new Cyclops Blink malware

Security researchers at Sophos and Cisco report that a suspected Russian state actor, previously tied to the Sandworm group linked to Russia's GRU, is exploiting two vulnerabilities in Cisco's Secure Firewall Management Center software. The attackers chain a maximum-severity authentication bypass flaw with a lower-severity privilege escalation bug to install a reverse shell and then deploy an updated version of the Cyclops Blink implant, which can steal credentials, map internal networks, and intercept live traffic.