discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco FMC vulnerabilities exploited by ransomware and state-sponsored hackers

By Lawrence Abrams·Sep 10·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Image: bleepingcomputer.com

Cisco's Secure Firewall Management Center (FMC) devices were compromised using two recently patched vulnerabilities, leading to attacks by ransomware and state-sponsored groups.

Why it matters

This highlights the importance of timely patching and the potential risks of unpatched security flaws in critical infrastructure.

Cisco's FMC devices had two security flaws that were fixed. Hackers found these flaws and used them to steal information and spread malware. This shows that even big companies can have security problems.

Analysis

{"heading_1":"Talos Analysis","subheading_1":"CVE-2026-20079 and CVE-2026-20316","content_1":"Talos identified three threat clusters associated with state-sponsored and crimeware actors. CVE-2026-20079 is a maximum-severity authentication bypass flaw, while CVE-2026-20316 is a static credential vulnerability.","subheading_2":"Qilin Ransomware and Cyclops Blink","content_2":"One cluster used Qilin ransomware, while another used Cyclops Blink malware. Both are known for destructive attacks.","subheading_3":"UAT-11823 and UAT-12197","content_3":"UAT-11823 and UAT-12197 used CVE-2026-20079 and CVE-2026-20316 to deploy web shells and steal credentials. UAT-11823 also used a variant of Cyclops Blink.","subheading_4":"UAT-11988","content_4":"UAT-11988 used Qilin ransomware, which was attributed to Qilin ransomware affiliates. They collected and staged sensitive data, then deployed a Python SOCKS5 proxy and reverse SSH tunnel."}

Key points

  • Cisco FMC devices were compromised using two recently patched vulnerabilities
  • The vulnerabilities were exploited by ransomware and state-sponsored hackers
  • Three threat clusters were identified by Talos
  • Qilin ransomware and Cyclops Blink were used in the attacks
  • The vulnerabilities were CVE-2026-20079 and CVE-2026-20316
The Upside

Timely patching of security flaws can prevent these kinds of attacks. Companies should always keep their software up to date.

The Downside

Hackers are always finding new ways to exploit security flaws. Companies need to be extra careful and vigilant to protect their systems.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityciscofmcvulnerabilitiesransomwarestate-sponsored

Author

Lawrence Abrams

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 10, 2026

Source

bleepingcomputer.com

Share

Topics

securityciscofmcvulnerabilitiesransomwarestate-sponsored

Related

More from this desk

Oct 7·thehackernews.com

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.

Oct 7·bleepingcomputer.com

Microsoft Outlook to block MSIX attachments starting November

Microsoft Outlook to block MSIX attachments starting November 2026.

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.