Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
ID: 43a5cbfe-d577-54d5-b057-f4742b6f05d6
STIX ID: report--43a5cbfe-d577-54d5-b057-f4742b6f05d6
Feed Name: Security Affairs
Threat Score
Cisco Talos reported three distinct clusters exploiting two patched Cisco FMC vulnerabilities (CVE-2026-20079 and CVE-2026-20316) to bypass authentication, deploy JSP web shells and Java-based command executors, steal credentials, install persistent malware such as Cyclops Blink, and ultimately enable Qilin ransomware deployments; the activity involves both criminal and state-linked actors and includes extensive post-compromise reconnaissance, proxying, and AV evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
