Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Yemen’s Houthis reportedly seize strategic Red Sea port of Mokha

    September 10, 2026

    Bernie Sanders, Alexandria Ocasio-Cortez invited to Paris for Gabriel Zucman’s tax-the-rich summit – POLITICO

    September 10, 2026

    The Guardian view on falling birthrates: cash alone cannot buy belonging | Editorial

    September 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Yemen’s Houthis reportedly seize strategic Red Sea port of Mokha
    • Bernie Sanders, Alexandria Ocasio-Cortez invited to Paris for Gabriel Zucman’s tax-the-rich summit – POLITICO
    • The Guardian view on falling birthrates: cash alone cannot buy belonging | Editorial
    • Forgetful Farage shares rose-tinted memories of Reform’s party conference | John Crace
    • ECB prepares for ‘longer-lasting’ inflation as it lifts interest rates to 2.5%
    • Electric air taxis get the green light for test flights in Texas
    • Introducing ChatGPT for Financial Services
    • Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 10, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.

    The attacks exploited CVE-2026-20079, a maximum-severity authentication bypass flaw, and CVE-2026-20316, a static credential vulnerability that allows attackers to log in using a low-privileged account.

    According to a new Cisco Talos report, the three clusters used compromised FMC devices to deploy web shells, steal credentials, create reverse shells and proxies, and in some attacks, deploy Qilin ransomware and Cyclops Blink malware.

    “Talos’ analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors,” Cisco Talos said.

    The company is tracking the clusters as UAT-12197, UAT-11823, and UAT-11988.

    CVE-2026-20079 has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts as root on vulnerable FMC devices.

    CVE-2026-20316 has a CVSS score of 5.3 and allows attackers to log in to FMC using static credentials for a low-privileged account. However, Cisco rates the flaw as High severity because it can be combined with other FMC vulnerabilities to elevate privileges.

    Cisco has already released hot fixes for both vulnerabilities and is urging customers to install them immediately. The company is also releasing a more comprehensive hardening that includes patches for additional vulnerabilities next week.

    Qilin ransomware deployed after FMC breach

    Talos attributed one of the intrusion clusters, tracked as UAT-11988, with high confidence to Qilin ransomware affiliates.

    The threat actor accessed an FMC device using static credentials associated with CVE-2026-20316, then abused legitimate built-in FMC tools to perform reconnaissance of the victim’s network.

    The attackers collected hostnames, IP addresses, directory listings, Active Directory service account credentials, MySQL credentials, domain account information, computer lists, and hostname-to-IP address mappings for internal servers and infrastructure.

    Talos says the collected information was staged in publicly accessible files on the compromised FMC server and downloaded using HTTP GET requests.

    The attackers then deployed a Python SOCKS5 proxy and reverse SSH tunnel to maintain access to internal systems and forwarded ports for LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM.

    After reconnaissance, the threat actor used post-exploitation tools including Impacket, Invoke-TheHash, and custom EDR killers.

    Ultimately, the attackers deployed Qilin ransomware on endpoints to encrypt files.

    APT hackers deploy Cyclops Blink

    A second intrusion cluster, tracked as UAT-11823, was attributed by Talos with high confidence to an advanced persistent threat actor whose tooling overlaps with the Sandworm APT group.

    Sandworm is a Russian state-sponsored hacking group linked to the Russia’s military intelligence agency, GRU, and is known for conducting destructive cyberattacks against governments and critical infrastructure.

    The attackers gained access to FMC devices either by exploiting CVE-2026-20079 or using the static credentials associated with CVE-2026-20316.

    After gaining access, the threat actors modified a license.tmp file to establish a Netcat-based reverse shell connecting to their command-and-control infrastructure. The malicious license file was then executed as root using Cisco’s legitimate package_info.pl utility.

    Talos says it believes UAT-11823 exploited both CVE-2026-20079 and CVE-2026-20316 during the attacks.

    The attackers also deployed scripts that collected configuration data from managed devices and stored it in archives for later exfiltration.

    UAT-11823 ultimately deployed a variant of Cyclops Blink on compromised devices, a modular Linux malware family previously attributed to the Russian Sandworm threat group.

    The Cyclops Blink variant acts as a backdoor, providing persistent access, credential theft, and the ability to sniff network traffic.

    Third cluster steals credentials

    The third cluster, tracked as UAT-12197, exploited CVE-2026-20079 and deployed a JSP-based web shell into the Cisco Security Manager Tomcat webroot directory.

    The web shell was then used to install a malicious JAR file named cmd.jar, which allowed them to execute commands on the server.

    The attackers used this JAR file to query internal databases on compromised systems and steal user authentication data and credentials.

    Confirms link between July attacks

    The Talos report also answered ongoing questions about the exploitation of the two vulnerabilities first disclosed in July.

    As BleepingComputer reported on July 29, Cisco disclosed that CVE-2026-20316 was being actively exploited and warned that it could be chained with other FMC vulnerabilities to elevate privileges.

    At the same time, Cisco updated its advisory for CVE-2026-20079 with the same /var/tmp/license.tmp indicator of compromise used for CVE-2026-20316, but did not confirm that the authentication bypass flaw was also being exploited.

    BleepingComputer contacted Cisco at the time to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 was also being exploited, and why the same indicator appeared in both advisories.

    Cisco did not answer those questions directly, instead just sharing a statement urging customers to install the hotfixes as soon as possible.

    Talos has now confirmed that UAT-11823 exploited both vulnerabilities and used the malicious license.tmp mechanism during its attacks.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Cisco Exploited flaws FMC gang hackers ransomware statesponsored
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI-powered attack exploited PaperCut flaws to hack 395 organizations

    Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

    Anthropic Researcher Resigns With Warning About the Dangers of AI Development

    Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster

    Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

    Microsoft says September updates fix mouse settings reset issues

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Yemen’s Houthis reportedly seize strategic Red Sea port of Mokha

    September 10, 2026

    Bernie Sanders, Alexandria Ocasio-Cortez invited to Paris for Gabriel Zucman’s tax-the-rich summit – POLITICO

    September 10, 2026

    The Guardian view on falling birthrates: cash alone cannot buy belonging | Editorial

    September 10, 2026

    Forgetful Farage shares rose-tinted memories of Reform’s party conference | John Crace

    September 10, 2026
    Latest Posts

    Mathematicians prove perfectly fair elections are impossible

    August 2, 2026

    Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

    August 2, 2026

    Foldables are sort of boring now — and that’s great news for Apple

    August 2, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Yemen’s Houthis reportedly seize strategic Red Sea port of Mokha

    September 10, 2026

    Bernie Sanders, Alexandria Ocasio-Cortez invited to Paris for Gabriel Zucman’s tax-the-rich summit – POLITICO

    September 10, 2026

    The Guardian view on falling birthrates: cash alone cannot buy belonging | Editorial

    September 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.