Cisco Talos has identified active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) software, with state-sponsored hacking groups and a ransomware affiliate leveraging the flaws to gain root access, deploy malware, and orchestrate attacks on enterprise networks. This incident marks one of the year's most serious enterprise security incidents, given FMC's role as the central console for managing fleets of Cisco firewalls. The second flaw, CVE-2026-20316, is rated at 5.3 on the CVSS scale but stems from hardcoded, static credentials linked to a low-privileged account, allowing remote attackers to log in without proper authorization.
Cyclops Blink's variant on compromised FMC systems includes persistence via init.d scripts, DNS-over-HTTPS command-and-control resolution, credential harvesting, packet sniffing, and remote command execution capabilities.
The third cluster, UAT-11988, is deemed a Qilin ransomware operator that bypassed authentication entirely, logging in through a static-credential flaw before executing live off the land using FMC's own built-in administrative tooling. The group harvested Active Directory and MySQL credentials, mapped domain controllers, file servers, and Exchange infrastructure, then tunneled deeper into victim networks over LDAP, Kerberos, SMB, NetBIOS, and WinRM using a Python SOCKS5 proxy and reverse-SSH connections. The IOC cluster description includes b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell, db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar — JAR-based command executor, and 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware sample.












