Cisco FMC actively exploited; BlueMoon exploit kit chains Chrome & Windows; AI tokens bypass MFA
ID: 6fdb1935-7dc3-5bcf-9a6c-f92bd5de51b7
STIX ID: report--6fdb1935-7dc3-5bcf-9a6c-f92bd5de51b7
Feed Name: defend.network
**TL;DR:** Multiple high-risk, actively exploited incidents: a critical Cisco Secure FMC authentication-bypass (CVE-2026-20079) is being exploited in the wild; the BlueMoon exploit kit chains Chrome and Windows flaws and is used by at least four China-aligned APT clusters; infostealer malware (Lumma, Vidar) is harvesting replayable AI tokens that can bypass MFA, risking unauthorized access to AI platforms; additionally, AdaptHealth suffered a 4.1M-person data exposure and U.S. authorities disrupted the Xinbi scam marketplace—urgent actions recommended include patching FMC, rotating AI API keys, and enforcing hardware MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
