Select a theme from the list.
Insights

From our experts

Latest
Telegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National BordersRansomware Crews Turn VMware vCenter Flaw Into a Virtual Infrastructure CrisisCisco Email Gateways Face Root-Level Takeover Through Weaponized MessagesPhishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareGitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to IntrudersTelegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National BordersRansomware Crews Turn VMware vCenter Flaw Into a Virtual Infrastructure CrisisCisco Email Gateways Face Root-Level Takeover Through Weaponized MessagesPhishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareGitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to Intruders
Security Insight

Cisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin Ransomware

Cisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin Ransomware
Photo by Rafael Minguet Delgado on Pexels

Attackers are exploiting two Cisco Secure Firewall Management Center vulnerabilities in operations linked to both state-sponsored groups and ransomware criminals. Observed activity includes credential theft, configuration harvesting, persistent network access and the deployment of Qilin ransomware. ([thehackernews.com](https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html?utm_source=openai))

News Date: 2026-09-11

Cisco Secure Firewall Management Center, commonly known as FMC, has become the entry point for several serious intrusion campaigns. Researchers identified three separate threat clusters exploiting CVE-2026-20079 and CVE-2026-20316, demonstrating how a compromised security-management appliance can provide attackers with privileged access to the wider enterprise.

A Security Console Becomes an Attack Platform

CVE-2026-20079 is a critical authentication bypass that can let a remote, unauthenticated attacker execute commands with root privileges. CVE-2026-20316 can provide unauthorized access through a low-privilege account and may be combined with other weaknesses to expand control.

The post-compromise activity differed by attacker. One cluster installed web shells and queried internal databases for authentication information. A second harvested managed-device configurations and deployed a Cyclops Blink variant associated with sophisticated state-backed operations. A third used built-in FMC capabilities for reconnaissance before collecting credentials, disabling security tools and deploying Qilin ransomware against selected endpoints.

Why FMC Compromise Is Especially Dangerous

Firewall management systems contain valuable intelligence about protected networks. They may expose device inventories, security policies, administrative accounts, network routes and configuration data. An attacker controlling the management layer can therefore understand the environment before moving deeper into it.

In my view, this incident should change how organizations classify security appliances. They are not simply defensive infrastructure. They are privileged administrative systems and should receive protections comparable to domain controllers, virtualization consoles and cloud-management portals.

Recommended Defensive Actions

  • Install the Cisco hotfixes for all affected FMC versions immediately.
  • Remove management interfaces from direct internet exposure.
  • Restrict administrative access through dedicated networks, VPN controls and strong authentication.
  • Review FMC logs for Cisco's published indicators of compromise.
  • Rotate credentials and secrets accessible from a potentially compromised appliance.
  • Contact Cisco support if exploitation is suspected, since patching does not remove an existing intrusion.

I believe defenders should assume that exploitation of an edge management product can lead to a complete network-security failure. Patching closes the vulnerability, but incident response must also determine what attackers learned, which credentials they obtained and whether persistence remains elsewhere in the environment.

Talk to our team →

Latest

Telegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National BordersSep 16, 2026Ransomware Crews Turn VMware vCenter Flaw Into a Virtual Infrastructure CrisisSep 16, 2026Cisco Email Gateways Face Root-Level Takeover Through Weaponized MessagesSep 16, 2026Phishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterSep 14, 2026Claude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketSep 14, 2026Check Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockSep 14, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path