INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Self-Rewriting Agents Exploit Critical Cisco FMC Flaw
| 2026-09-17 17:32 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A sophisticated cyber threat landscape is unfolding, with multiple incidents and groups exploiting vulnerabilities to wreak havoc. The Chinese Advanced Persistent Threat (APT) has been found to be targeting the flaw in various countries' critical infrastructure, while a new class of electromagnetic side-channel attacks called InjectEave has demonstrated its potential for leaking sensitive information from external RF signals. Researchers have also identified several high-profile incidents involving Russia's Black Axe cybercrime syndicate, including wire fraud and money laundering charges against alleged leaders extradited to the US. These cases highlight the ever-evolving nature of modern cybersecurity threats, requiring swift action and effective countermeasures to protect against these emerging risks.
Technical Mitigations AI-generated
* Use secure authentication mechanisms, such as multi-factor authentication (MFA), to prevent unauthorized access to systems and data.
* Regularly update and patch software and operating systems to ensure that known vulnerabilities are addressed before they can be exploited by attackers.
* Implement a robust firewall configuration to block suspicious traffic and prevent unauthorized access to networks and systems.
* Use encryption to protect sensitive data both in transit (e.g., HTTPS) and at rest (e.g., encrypted storage).
* Conduct regular security audits and vulnerability assessments to identify potential weaknesses and address them before they can be exploited by attackers.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
lu•••••.io
RE•••••.txt
so•••••.py
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CasbaneiroCasbaneiroAmadeyAmadeyCyclops BlinkCyclops BlinkQilinQilin
CVE-2026-20079CVE-2026-20079
CVE-2026-20316CVE-2026-20316
CVE-2026-59310CVE-2026-59310
Target & Sectors
DACH
DACH
NORTH_AMERICA
NORTH_AMERICA
LATAM
LATAM
cryptocurrencycryptocurrency
financefinance
governmentgovernment
manufacturingmanufacturing
retailretail
technologytechnology
Incident Timeline
at least August 2022
Vectra, a rebranded Vecty company, exploited a Cisco FMC critical flaw in ransomware attacks targeting at least August 2022.
Click on any entity below to view its context and source!
organisation
Vectra
The operator "Vectra" is a rebrand of "Nyxel," active since at least August 2022.
September 8, 2023
Threat actors exploited a previously unknown critical Cisco FMC flaw to gain unauthorized access and launch ransomware attacks on targeted organizations.
between September 8, 2023
Threat actors used a Cisco FMC flaw to target suspected digital asset investment scams.
Click on any entity below to view its context and source!
organisation
The U.S. Department
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
organisation
Treasury
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
organisation
Financial Crimes Enforcement Network
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
general_metric
33,904 Bank Secrecy Act
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
financial
$12.7 December
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
May 2025
Threat actors exploited a critical Cisco FMC flaw in the targeted systems.
Click on any entity below to view its context and source!
source_region
Cyprus
One involves
Searzhudin Aktulayev
, 40, who was arrested in Cyprus in May 2025 and extradited to the U.S. on August 28, 2026.
July 2025
Threat actors exploited a critical Cisco FMC flaw to distribute the OfferLoader custom loader between July 2025 and April 2026.
Click on any entity below to view its context and source!
organisation
OfferLoader
Both these chains lead to a custom loader called OfferLoader that has delivered three payloads between July 2025 and April 2026:
November 2025
Threat actors exploited a critical Cisco FMC flaw to target Sergei Filimonov and Denis Obrezko.
Click on any entity below to view its context and source!
source_region
Russian Federation
The two other cases relate to Russian web developer
Sergei Filimonov
and
Denis Obrezko
, who was arrested in Thailand in November 2025 and was
extradited
to the U.S. in June in connection with a large-scale cyber espionage campaign being carried out by a group known as Void Blizzard.
source_region
Thailand
The two other cases relate to Russian web developer
Sergei Filimonov
and
Denis Obrezko
, who was arrested in Thailand in November 2025 and was
extradited
to the U.S. in June in connection with a large-scale cyber espionage campaign being carried out by a group known as Void Blizzard.
tactic
Espionage
The two other cases relate to Russian web developer
Sergei Filimonov
and
Denis Obrezko
, who was arrested in Thailand in November 2025 and was
extradited
to the U.S. in June in connection with a large-scale cyber espionage campaign being carried out by a group known as Void Blizzard.
malware
Denis
The two other cases relate to Russian web developer
Sergei Filimonov
and
Denis Obrezko
, who was arrested in Thailand in November 2025 and was
extradited
to the U.S. in June in connection with a large-scale cyber espionage campaign being carried out by a group known as Void Blizzard.
December 2025
The Justice Department discovered a critical Cisco FMC flaw exploited in ransomware attacks.
Click on any entity below to view its context and source!
organisation
the Justice Department
"In December 2025, the defendants traveled from Indiana to Kansas to attempt to steal cash from ATMs in Wamego and Manhattan through jackpotting," the Justice Department
said
.
December 31, 2025
Threat actors exploited a critical Cisco FMC flaw in ransomware attacks targeting overseas scam centers.
Click on any entity below to view its context and source!
organisation
The U.S. Department
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
organisation
Treasury
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
organisation
Financial Crimes Enforcement Network
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
general_metric
33,904 Bank Secrecy Act
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
financial
$12.7 December
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
April 2026
Threat actors exploited a critical Cisco FMC flaw to target the ransomware attack chain, which delivered payloads via custom loader OfferLoader starting from July 2025.
Click on any entity below to view its context and source!
organisation
OfferLoader
Both these chains lead to a custom loader called OfferLoader that has delivered three payloads between July 2025 and April 2026:
June 2026
Threat actors used a Cisco FMC flaw to target entities in the U.S., Germany, and other countries.
Click on any entity below to view its context and source!
industry
Technology
Settra emerged in June 2026 and has mainly targeted entities in the U.S., Germany, the U.K., Canada, and Australia spanning technology, professional services, manufacturing, and retail sectors, according to researcher
Rakesh Krishnan
.
target_region
Germany
Settra emerged in June 2026 and has mainly targeted entities in the U.S., Germany, the U.K., Canada, and Australia spanning technology, professional services, manufacturing, and retail sectors, according to researcher
Rakesh Krishnan
.
target_region
Canada
Settra emerged in June 2026 and has mainly targeted entities in the U.S., Germany, the U.K., Canada, and Australia spanning technology, professional services, manufacturing, and retail sectors, according to researcher
Rakesh Krishnan
.
target_region
Australia
Settra emerged in June 2026 and has mainly targeted entities in the U.S., Germany, the U.K., Canada, and Australia spanning technology, professional services, manufacturing, and retail sectors, according to researcher
Rakesh Krishnan
.
industry
Manufacturing
Settra emerged in June 2026 and has mainly targeted entities in the U.S., Germany, the U.K., Canada, and Australia spanning technology, professional services, manufacturing, and retail sectors, according to researcher
Rakesh Krishnan
.
industry
Retail
Settra emerged in June 2026 and has mainly targeted entities in the U.S., Germany, the U.K., Canada, and Australia spanning technology, professional services, manufacturing, and retail sectors, according to researcher
Rakesh Krishnan
.
organisation
Zscaler ThreatLabz
It was identified by Zscaler ThreatLabz in June 2026.
July 23, weeks
The incident involved a critical Cisco FMC flaw that was exploited in ransomware attacks, with the vulnerability being publicly disclosed just weeks before Cisco announced it had been patched.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20079
The example log entry is dated July 23, weeks before Cisco says PSIRT became aware of exploitation of CVE-2026-20079 in August.
July 23
Threat actors used Cisco's July 23 hot fix for CVE-2026-20079 to exploit the vulnerability.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20079
"
Cisco's latest update now confirms that CVE-2026-20079 has been exploited, but does not clarify whether the July 23 activity included exploitation of both vulnerabilities.
July 29, 2026
Threat actors exploited a critical Cisco FMC flaw to target the affected system.
Click on any entity below to view its context and source!
organisation
Cisco Secure Firewall Management Center
Cisco did not answer the questions directly and instead shared the following statement:
"On July 29, 2026, Cisco released software fixes to address vulnerabilities in Cisco Secure Firewall Management Center (FMC).
July 29
Threat actors exploited a Cisco FMC flaw, CVE-2026-20316, which was being actively targeted in ransomware attacks.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20316
As
BleepingComputer reported on July 29
, Cisco disclosed that CVE-2026-20316 was being actively exploited and warned that it could be chained with other FMC vulnerabilities to elevate privileges.
On July 29, Cisco
disclosed another Secure FMC vulnerability
, tracked as CVE-2026-20316, caused by static credentials for a low-privileged account.
organisation
Secure FMC
On July 29, Cisco
disclosed another Secure FMC vulnerability
, tracked as CVE-2026-20316, caused by static credentials for a low-privileged account.
general_metric
20316 CVE-2026
On July 29, Cisco
disclosed another Secure FMC vulnerability
, tracked as CVE-2026-20316, caused by static credentials for a low-privileged account.
August 2026
Sophos detected a ransomware attack using Cyclops Blink on Cisco FMC devices in Latin America.
Click on any entity below to view its context and source!
source_region
China
In August 2026, German incident response company QUIRSO uncovered evidence that a China-nexus advanced persistent threat (APT) has been exploiting the flaw shortly after public disclosure.
source_region
Germany
In August 2026, German incident response company QUIRSO uncovered evidence that a China-nexus advanced persistent threat (APT) has been exploiting the flaw shortly after public disclosure.
organisation
APT
In August 2026, German incident response company QUIRSO uncovered evidence that a China-nexus advanced persistent threat (APT) has been exploiting the flaw shortly after public disclosure.
industry
Legal
Casbaneiro hits Latin America
A
Casbaneiro
attack campaign was observed targeting users in Latin America in August 2026, using phishing emails and PDF files themed around fake invoices and legal notices as an initial access vector.
tactic
Phishing
Casbaneiro hits Latin America
A
Casbaneiro
attack campaign was observed targeting users in Latin America in August 2026, using phishing emails and PDF files themed around fake invoices and legal notices as an initial access vector.
target_region
LATAM
Casbaneiro hits Latin America
A
Casbaneiro
attack campaign was observed targeting users in Latin America in August 2026, using phishing emails and PDF files themed around fake invoices and legal notices as an initial access vector.
malware
Casbaneiro
Casbaneiro hits Latin America
A
Casbaneiro
attack campaign was observed targeting users in Latin America in August 2026, using phishing emails and PDF files themed around fake invoices and legal notices as an initial access vector.
organisation
PDF
Casbaneiro hits Latin America
A
Casbaneiro
attack campaign was observed targeting users in Latin America in August 2026, using phishing emails and PDF files themed around fake invoices and legal notices as an initial access vector.
tactic
Botnet
Cyclops Blink returns on Cisco FMC
Sophos said it observed a variant of Cyclops Blink, a modular botnet and malware framework, on multiple compromised Cisco Firewall Management Center (FMC) devices in August 2026.
malware
Cyclops Blink
Cyclops Blink returns on Cisco FMC
Sophos said it observed a variant of Cyclops Blink, a modular botnet and malware framework, on multiple compromised Cisco Firewall Management Center (FMC) devices in August 2026.
organisation
Cisco FMC
Cyclops Blink returns on Cisco FMC
Sophos said it observed a variant of Cyclops Blink, a modular botnet and malware framework, on multiple compromised Cisco Firewall Management Center (FMC) devices in August 2026.
organisation
Sophos
Cyclops Blink returns on Cisco FMC
Sophos said it observed a variant of Cyclops Blink, a modular botnet and malware framework, on multiple compromised Cisco Firewall Management Center (FMC) devices in August 2026.
organisation
Cisco Firewall Management Center
Cyclops Blink returns on Cisco FMC
Sophos said it observed a variant of Cyclops Blink, a modular botnet and malware framework, on multiple compromised Cisco Firewall Management Center (FMC) devices in August 2026.
organisation
FMC
Cyclops Blink returns on Cisco FMC
Sophos said it observed a variant of Cyclops Blink, a modular botnet and malware framework, on multiple compromised Cisco Firewall Management Center (FMC) devices in August 2026.
vulnerability
CVE-2026-20079
"In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," Cisco updated its
CVE-2026-20079 advisory
to say on Wednesday.
August 28, 2026
Threat actors exploited a critical Cisco FMC flaw to target Searzhudin Aktulayev, 40.
Click on any entity below to view its context and source!
source_region
Cyprus
One involves
Searzhudin Aktulayev
, 40, who was arrested in Cyprus in May 2025 and extradited to the U.S. on August 28, 2026.
2026/09/09
Threat actors exploited CVE-2026-20079 in Cisco FMC systems to target Federal Civilian Executive Branch agencies.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20079
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
tactic
T1588.006 - Vulnerabilities
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
general_metric
20079 CVE-2026
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
attribution
KEV
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
attribution
Known Exploited
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
attribution
Federal Civilian Executive Branch
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
September 11, 2026
Threat actors used a critical Cisco FMC flaw to deploy Qilin ransomware.
Click on any entity below to view its context and source!
tactic
Ransomware
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Pierluigi Paganini
September 11, 2026
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware.
organisation
Cisco FMC
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Pierluigi Paganini
September 11, 2026
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware.
malware
Qilin
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Pierluigi Paganini
September 11, 2026
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware.
September 12, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20079
CISA
added
CVE-2026-20079 to its KEV catalog, requiring U.S. federal agencies to patch it by September 12, 2026.
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
attribution
KEV
CISA
added
CVE-2026-20079 to its KEV catalog, requiring U.S. federal agencies to patch it by September 12, 2026.
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
tactic
T1588.006 - Vulnerabilities
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
general_metric
20079 CVE-2026
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
attribution
Known Exploited
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
attribution
Federal Civilian Executive Branch
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
2026/09/12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered Federal Civilian Executive Branch agencies to secure vulnerable Cisco FMC systems by September 12, 2026 due to a critical CVE-2026-20079 flaw.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20079
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
tactic
T1588.006 - Vulnerabilities
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
general_metric
20079 CVE-2026
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
attribution
KEV
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
attribution
Known Exploited
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
attribution
Federal Civilian Executive Branch
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
Sep 17, 2026
Threat actors exploited a previously unknown critical Cisco FMC flaw to gain unauthorized access and launch ransomware attacks on targeted organizations.
May 2018 to November 2019
Carter was ordered to pay $99,528 in restitution for a critical Cisco FMC flaw exploited in ransomware attacks that occurred between May 2018 and November 2019.
Click on any entity below to view its context and source!
financial
$99,528 November
Carter, who worked at the store from May 2018 to November 2019, has also been ordered to pay $99,528 in restitution.
2026/09/17
Threat actors used social media websites, online dating websites, and voice over internet protocol phone numbers to find victims in the United States.
Click on any entity below to view its context and source!
organisation
APT
APT hackers deploy Cyclops Blink
A second intrusion cluster, tracked as UAT-11823, was attributed by Talos with high confidence to an advanced persistent threat actor whose tooling overlaps with the Sandworm APT group.
organisation
Sandworm APT
APT hackers deploy Cyclops Blink
A second intrusion cluster, tracked as UAT-11823, was attributed by Talos with high confidence to an advanced persistent threat actor whose tooling overlaps with the Sandworm APT group.
organisation
RF
RF signals leak analog secrets
A group of academics from the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University has demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog secrets.
organisation
the Hong Kong Polytechnic University
RF signals leak analog secrets
A group of academics from the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University has demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog secrets.
organisation
InjectEave
RF signals leak analog secrets
A group of academics from the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University has demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog secrets.
infrastructure
Linux
UAT-11823 ultimately deployed a variant of Cyclops Blink on compromised devices, a modular Linux malware family previously
attributed to the Russian Sandworm threat group
.
"While it retains familiar Mirai-style botnet functionality, it stands out for its unusually broad capability set, including multiple Linux n-day local privilege escalation exploits, extensive persistence coverage across Linux and embedded environments, encrypted C2 communications, anti-analysis checks, and decoy traffic," Nozomi Networks
said
.
"Unlike the WatchGuard-focused samples documented in 2022, the 2026 variant runs on x86-64 Linux and uses generic System V (SysV) persistence rather than vendor-specific firmware modification," Sophos
said
.
"In this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process."
KATARU brute-forces Telnet access
An IoT malware dubbed KATARU has leveraged Telnet credential brute-forcing to break into Linux and embedded systems.
organisation
Sandworm
UAT-11823 ultimately deployed a variant of Cyclops Blink on compromised devices, a modular Linux malware family previously
attributed to the Russian Sandworm threat group
.
“The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:”
The second cluster, attributed to the advanced persistent threat actor UAT-11823 with tooling overlapping Sandworm, establishes Netcat reverse shells, harvests device configurations, and installs the modular ELF malware “
Cyclops Blink
” for persistent access, DNS over HTTPS resolution, and packet sniffing.
data_breach
127 AWS credential records
Post-compromise activity included exfiltration from a workstation associated with the Thai military and collection of 127 AWS credential records."
organisation
Black Axe
Black Axe leaders extradited
Five alleged Nigeria-based leaders of the
Black Axe
cybercrime syndicate (Perry Osagiede, Franklyn Edosa Osagiede, Osariemen Eric Clement, Collins Owhofasa Otughwor, and Musa Mudashiru), known for their involvement in global-scale cyber-enabled financial fraud, have been extradited from South Africa to the U.S. to face wire fraud and money laundering charges.
organisation
Ploutus
Eight-year sentence for ATM jackpotting
In more ATM jackpotting action, another 27-year-old from Venezuela, Juan Manuel Gouveia-Aguilera, has been sentenced to eight years in prison for his role in a conspiracy to deploy
Ploutus malware
and steal millions of dollars from ATMs in the U.S. Gouveia-Aguilera has also been ordered to pay restitution as part of his sentence.
organisation
Gouveia-Aguilera
Eight-year sentence for ATM jackpotting
In more ATM jackpotting action, another 27-year-old from Venezuela, Juan Manuel Gouveia-Aguilera, has been sentenced to eight years in prison for his role in a conspiracy to deploy
Ploutus malware
and steal millions of dollars from ATMs in the U.S. Gouveia-Aguilera has also been ordered to pay restitution as part of his sentence.
organisation
ATM
"
ATM jackpotting plot ends in guilty pleas
Five Venezuelan nationals have pleaded guilty to attempting to
steal U.S. currency from ATMs
.
organisation
VectraRAT MaaS
"Rather than developing their own models, many threat actors are offering access to uncensored or modified LLMs via AI-as-a-service schemes in the same way malware, phishing kits, and ransomware are commoditized."
VectraRAT MaaS hits the market
SOCRadar has disclosed details of a new malware-as-a-service (MaaS) platform called VectraRAT that's been built from scratch and is available for $250 a month.
organisation
VectraRAT
"Rather than developing their own models, many threat actors are offering access to uncensored or modified LLMs via AI-as-a-service schemes in the same way malware, phishing kits, and ransomware are commoditized."
VectraRAT MaaS hits the market
SOCRadar has disclosed details of a new malware-as-a-service (MaaS) platform called VectraRAT that's been built from scratch and is available for $250 a month.
infrastructure
Windows
"Casbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use of fake windows to facilitate fraudulent activities," Fortinet FortiGuard Labs
said
.
"In this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process."
KATARU brute-forces Telnet access
An IoT malware dubbed KATARU has leveraged Telnet credential brute-forcing to break into Linux and embedded systems.
Docro Hijacker (a Chrome backdoor that can bypass
modern integrity protections
), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a
previously unnamed cross-platform backdoor
that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS.
"In the observed intrusions, attackers deployed remote monitoring and management (RMM) tools for persistence and then encrypted files, dropped RESTORE_FILES.txt ransom notes, cleared Windows event logs, and disabled Windows recovery options.
One incident also included signs of Bring Your Own Vulnerable Driver (BYOVD); as well as a notable misspelling by the threat actors during the attack, which left them unable to clear the Windows Defender Event Log."
"It pairs a Go control server called VectraHub, with a Vue3 operator panel compiled into the binary, with a native C++ Windows implant.
The .NET RAT is designed for persistent and interactive control over compromised Windows systems.
Azalea RAT arrives in the form of a Windows shortcut that masquerades as a PDF document to trigger the execution of a first-stage loader, which then performs anti-analysis checks before extracting a DLL that's responsible for setting up Microsoft Defender exclusion paths and ultimately launching the RAT.
The AutoIT script is designed to decrypt the payload in memory and inject it into a Microsoft-signed Windows process.
organisation
The Spanish Data Protection Agency
"
AI agent linked to data breach
The Spanish Data Protection Agency (AEPD) said it was notified of a data breach that was allegedly executed by an AI agent.
organisation
Settra
"These mitigations raise the bar, but they do not guarantee immunity."
Settra ransomware expands attacks
A new ransomware group called Settra has deployed MeshAgent remote access software in two intrusions analyzed by Huntress.
organisation
MeshAgent
"These mitigations raise the bar, but they do not guarantee immunity."
Settra ransomware expands attacks
A new ransomware group called Settra has deployed MeshAgent remote access software in two intrusions analyzed by Huntress.
organisation
Huntress
"These mitigations raise the bar, but they do not guarantee immunity."
Settra ransomware expands attacks
A new ransomware group called Settra has deployed MeshAgent remote access software in two intrusions analyzed by Huntress.
organisation
Cynet
In
another case
investigated by Cynet, "the ransomware engine was buried inside an encrypted blob and gated behind an operator-supplied password.
organisation
SloppyRAT
ClickFix chain delivers SloppyRAT
A new malware called SloppyRAT, likely leveraged by a ransomware-related threat actor, is being delivered through a multi-stage ClickFix infection chain to establish a foothold for lateral movement.
organisation
Makeself
“After obtaining access, UAT-11823 subsequently updated the “license.tmp” file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server:”
The third cluster involves
Qilin ransomware
operators (UAT-11988) who use static credentials for initial access, perform extensive domain reconnaissance, deploy SOCKS proxies and reverse-SSH tunnels, and execute AV killers before deploying ransomware.
organisation
SSH
“After obtaining access, UAT-11823 subsequently updated the “license.tmp” file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server:”
The third cluster involves
Qilin ransomware
operators (UAT-11988) who use static credentials for initial access, perform extensive domain reconnaissance, deploy SOCKS proxies and reverse-SSH tunnels, and execute AV killers before deploying ransomware.
The attackers then deployed a Python SOCKS5 proxy and reverse SSH tunnel to maintain access to internal systems and forwarded ports for LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM.
organisation
AV
“After obtaining access, UAT-11823 subsequently updated the “license.tmp” file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server:”
The third cluster involves
Qilin ransomware
operators (UAT-11988) who use static credentials for initial access, perform extensive domain reconnaissance, deploy SOCKS proxies and reverse-SSH tunnels, and execute AV killers before deploying ransomware.
organisation
Invoke-TheHash
“The threat actor conducted extensive probing of endpoints in the victim’s environment, deployed open-source tooling such as impacket, Invoke-TheHash, and custom-made AV killers — all followed by the deployment of the Qilin ransomware on selected endpoints.”
organisation
FMC
According to a new Cisco Talos report, the three clusters used compromised FMC devices to deploy web shells, steal credentials, create reverse shells and proxies, and in some attacks, deploy Qilin ransomware and Cyclops Blink malware.
The second flaw can be chained with other FMC vulnerabilities to increase privileges.
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks.
organisation
Mirai
"While it retains familiar Mirai-style botnet functionality, it stands out for its unusually broad capability set, including multiple Linux n-day local privilege escalation exploits, extensive persistence coverage across Linux and embedded environments, encrypted C2 communications, anti-analysis checks, and decoy traffic," Nozomi Networks
said
.
organisation
Secure FMC
Cisco has
described
the Cyclops Blink activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software: CVE-2026-20079 and CVE-2026-20316.
organisation
ELF
“The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:”
The second cluster, attributed to the advanced persistent threat actor UAT-11823 with tooling overlapping Sandworm, establishes Netcat reverse shells, harvests device configurations, and installs the modular ELF malware “
Cyclops Blink
” for persistent access, DNS over HTTPS resolution, and packet sniffing.
organisation
DNS
“The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:”
The second cluster, attributed to the advanced persistent threat actor UAT-11823 with tooling overlapping Sandworm, establishes Netcat reverse shells, harvests device configurations, and installs the modular ELF malware “
Cyclops Blink
” for persistent access, DNS over HTTPS resolution, and packet sniffing.
organisation
HTTPS
“The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:”
The second cluster, attributed to the advanced persistent threat actor UAT-11823 with tooling overlapping Sandworm, establishes Netcat reverse shells, harvests device configurations, and installs the modular ELF malware “
Cyclops Blink
” for persistent access, DNS over HTTPS resolution, and packet sniffing.
organisation
EDR
After reconnaissance, the threat actor used post-exploitation tools including Impacket, Invoke-TheHash, and custom EDR killers.
By constantly altering the syntax and logic of its automated actions, the payload successfully evades static endpoint detection and response (EDR) signatures."
organisation
WatchGuard
"Unlike the WatchGuard-focused samples documented in 2022, the 2026 variant runs on x86-64 Linux and uses generic System V (SysV) persistence rather than vendor-specific firmware modification," Sophos
said
.
organisation
HTA
"In this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process."
KATARU brute-forces Telnet access
An IoT malware dubbed KATARU has leveraged Telnet credential brute-forcing to break into Linux and embedded systems.
organisation
IoT
"In this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process."
KATARU brute-forces Telnet access
An IoT malware dubbed KATARU has leveraged Telnet credential brute-forcing to break into Linux and embedded systems.
organisation
DDoS
The end goal is to establish communications with a C2 server and receive DDoS attack commands.
infrastructure
Macos
Docro Hijacker (a Chrome backdoor that can bypass
modern integrity protections
), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a
previously unnamed cross-platform backdoor
that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS.
organisation
Chrome
Docro Hijacker (a Chrome backdoor that can bypass
modern integrity protections
), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a
previously unnamed cross-platform backdoor
that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS.
organisation
ARKTunnel
Docro Hijacker (a Chrome backdoor that can bypass
modern integrity protections
), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a
previously unnamed cross-platform backdoor
that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS.
organisation
WebSocket
Docro Hijacker (a Chrome backdoor that can bypass
modern integrity protections
), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a
previously unnamed cross-platform backdoor
that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS.
organisation
Insomnia
Docro Hijacker (a Chrome backdoor that can bypass
modern integrity protections
), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a
previously unnamed cross-platform backdoor
that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS.
organisation
RMM
"In the observed intrusions, attackers deployed remote monitoring and management (RMM) tools for persistence and then encrypted files, dropped RESTORE_FILES.txt ransom notes, cleared Windows event logs, and disabled Windows recovery options.
organisation
the Windows Defender Event Log
One incident also included signs of Bring Your Own Vulnerable Driver (BYOVD); as well as a notable misspelling by the threat actors during the attack, which left them unable to clear the Windows Defender Event Log."
organisation
VectraHub
"It pairs a Go control server called VectraHub, with a Vue3 operator panel compiled into the binary, with a native C++ Windows implant.
organisation
DLL
Azalea RAT arrives in the form of a Windows shortcut that masquerades as a PDF document to trigger the execution of a first-stage loader, which then performs anti-analysis checks before extracting a DLL that's responsible for setting up Microsoft Defender exclusion paths and ultimately launching the RAT.
organisation
Microsoft Defender
Azalea RAT arrives in the form of a Windows shortcut that masquerades as a PDF document to trigger the execution of a first-stage loader, which then performs anti-analysis checks before extracting a DLL that's responsible for setting up Microsoft Defender exclusion paths and ultimately launching the RAT.
organisation
Microsoft
The AutoIT script is designed to decrypt the payload in memory and inject it into a Microsoft-signed Windows process.
organisation
CVE-2026-20079
CVE-2026-20079 has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts as root on vulnerable FMC devices.
Cisco first
disclosed CVE-2026-20079 in March
, when the company said it had no evidence that the vulnerability was being exploited in attacks.
organisation
CVSS
CVE-2026-20079 has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts as root on vulnerable FMC devices.
The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices.
organisation
JSP
Third cluster steals credentials
The third cluster, tracked as UAT-12197, exploited CVE-2026-20079 and deployed a JSP-based web shell into the Cisco Security Manager Tomcat webroot directory.
The first cluster deploys JSP-based web shells and custom command executors into Tomcat webroot directories to query internal databases and harvest user authentication data and credentials.
organisation
UAT-12197
Third cluster steals credentials
The third cluster, tracked as UAT-12197, exploited CVE-2026-20079 and deployed a JSP-based web shell into the Cisco Security Manager Tomcat webroot directory.
organisation
BleepingComputer
BleepingComputer contacted Cisco at the time to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 was also being exploited, and why the same indicator appeared in both advisories.
At the time, BleepingComputer contacted Cisco to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 had also been exploited, and whether Cisco intentionally added the shared indicator to both advisories.
organisation
Secure Firewall Management Center
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.
Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws.
infrastructure
Cursor
"Amatera targets data associated with Cline and Continue, while Remus targets Claude, Cursor, and OpenCode," Gen Digital
said
.
organisation
Claude
"Amatera targets data associated with Cline and Continue, while Remus targets Claude, Cursor, and OpenCode," Gen Digital
said
.
organisation
Hacking News / Cybersecurity News
Ravie Lakshmanan
Sep 17, 2026
Hacking News / Cybersecurity News
Attackers keep finding new keys.
organisation
CL-CRI-1171
Malware PPI operation exposed
A threat actor known as CL-CRI-1171 has stayed under the radar for at least two years, offering a pay-per-install (PPI) marketplace that allows other threat actors to distribute their malware through YouTube channels and a parallel search engine optimization (SEO)-poisoning funnel.
organisation
Palo Alto Networks Unit
"These channels were actively interacting with viewers to promote gaming content laced with links to download malware," Palo Alto Networks Unit 42
said
.
organisation
LocalAI
Exposed LocalAI instances compromised
A large-scale campaign has been found to target LocalAI instances exposed to the internet without authentication and achieve command execution inherent in MCP STDIO configuration.
organisation
MCP STDIO
Exposed LocalAI instances compromised
A large-scale campaign has been found to target LocalAI instances exposed to the internet without authentication and achieve command execution inherent in MCP STDIO configuration.
organisation
API
Additional compromise activity consisted of exploitation of legacy infrastructure, authentication bypass, a broad sweep of cryptocurrency wallets and API keys, and theft of AWS ECS task credentials.
organisation
ECS
Additional compromise activity consisted of exploitation of legacy infrastructure, authentication bypass, a broad sweep of cryptocurrency wallets and API keys, and theft of AWS ECS task credentials.
organisation
Irregular
Agents rewrite their own models
New research from Irregular has found that AI agents can retrain the model that powers them, in the process leaking secrets and eliminating refusals the model had been previously trained to enforce.
organisation
Fortra
"It's hard not to sound like a broken record these days when talking about security updates," Tyler Reguly, Fortra's Associate Director of Security Research and Development, said.
organisation
Security Research and Development
"It's hard not to sound like a broken record these days when talking about security updates," Tyler Reguly, Fortra's Associate Director of Security Research and Development, said.
organisation
SIM
"
Insider SIM swaps draw prison term
Former Oregon-based AT&T Store employee, Kenneth Carter, 44, has been
sentenced to 16 months
in prison for abusing his access to perform SIM swaps that helped criminals take over customers' bank accounts.
organisation
AT&T Store
"
Insider SIM swaps draw prison term
Former Oregon-based AT&T Store employee, Kenneth Carter, 44, has been
sentenced to 16 months
in prison for abusing his access to perform SIM swaps that helped criminals take over customers' bank accounts.
organisation
Mandiant
AI drives malware evasion
Google-owned Mandiant said it has observed advanced malware campaigns using embedded, lightweight AI models to facilitate stealthy, long-term persistence within victim networks.
organisation
EM
"We demonstrate eavesdropping on audio played through wired and wireless headphones from up to 30 m away, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets."
organisation
Uncensored AI
"
Uncensored AI sold underground
A threat actor named Optimus_Prime (aka OptimusPrimero) is advertising an uncensored AI subscription service named Luciferus on the Exploit underground forum as an alternative to jailbreaking mainstream providers like ChatGPT, Claude, or Gemini.
organisation
OptimusPrimero
"
Uncensored AI sold underground
A threat actor named Optimus_Prime (aka OptimusPrimero) is advertising an uncensored AI subscription service named Luciferus on the Exploit underground forum as an alternative to jailbreaking mainstream providers like ChatGPT, Claude, or Gemini.
organisation
Telegram
"The emergence of Luciferus aligns with a broader trend in which threat actors are increasingly commercializing AI through underground forums, Telegram channels, and cybercriminal marketplaces," Sophos said.
organisation
TCP
The two speak a proprietary binary TCP protocol using MessagePack over port 3308."
organisation
MessagePack
The two speak a proprietary binary TCP protocol using MessagePack over port 3308."
organisation
ClickFix
The malware is delivered via Amadey and ClickFix lure pages.
organisation
MCP
Infostealers target AI agent data
Infostealers like Amatera and Remus are expanding their data collection focus beyond browser passwords and cryptocurrency wallets to collect access tokens, MCP configurations, prompt histories, and project data stored by AI tools.
organisation
EtherHiding
"The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks,
EtherHiding
for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques," ThreatLabz
said
.
organisation
ThreatLabz
"The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks,
EtherHiding
for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques," ThreatLabz
said
.
organisation
XOR
"The batch file launches PowerShell with a hidden window and a disabled profile, then reassembles a Base64 payload from ten fragments, strips deliberately inserted junk characters, and decodes it through repeating key XOR," Point Wild
said
.
organisation
the U.S. Justice Department
"From at least 2011 through 2021, the Black Axe defendants and other conspirators worked together from Cape Town to engage in widespread internet fraud involving romance scams and advance fee schemes," the U.S. Justice Department
said
.
organisation
Royder Adrian Figuera-Perez
Luis Alberto Velasquez-Artigas, 27, Royder Adrian Figuera-Perez, 29, Javier Mejia, Jr, 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26, all pleaded guilty to one count of conspiracy to commit bank larceny.
organisation
Italo Lizandro Corrales-Carrillo
Luis Alberto Velasquez-Artigas, 27, Royder Adrian Figuera-Perez, 29, Javier Mejia, Jr, 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26, all pleaded guilty to one count of conspiracy to commit bank larceny.
organisation
the U.S. Federal Bureau of Investigation
According to the U.S. Federal Bureau of Investigation, 1,900 incidents have been recorded since 2020.
organisation
Court
"The Court found Gouveia-Aguilera to be responsible for more than $3.5 million in losses and this sentence is believed to be the longest federal sentence imposed for an individual’s role in ATM jackpotting," the Justice Department
said
.
infrastructure
23 servers
"Callback logs independently confirmed command execution with root privileges on 23 servers.
financial
$2,000 Carter
Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap.
infrastructure
11 commercial devices
"This vulnerability exists in ubiquitous nonlinear analog interfaces across the 11 commercial off-the-shelf devices we evaluated, allowing attackers to eavesdrop on headphone and landline audio, infer smart-fan speed and smart-lamp brightness, and recover other analog secrets that digital encryption and software defenses can hardly protect," the researchers
said
.
Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices.
victims
70 victims
The group has claimed
70 victims to date
.
financial
$35 service
The service costs $35 per month and claims to support three models on its website ("luciferus[.]io").
organisation
SMB
The attackers then deployed a Python SOCKS5 proxy and reverse SSH tunnel to maintain access to internal systems and forwarded ports for LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM.
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).” concludes the report.
organisation
NETBIOS
The attackers then deployed a Python SOCKS5 proxy and reverse SSH tunnel to maintain access to internal systems and forwarded ports for LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM.
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).” concludes the report.
organisation
Cisco Secure Firewall Management Center
Talos identified three attack clusters targeting Cisco Secure Firewall Management Center (FMC).
data_breach
445 SMB
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).” concludes the report.
data_breach
135 NETBIOS
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).” concludes the report.
organisation
Snort
Cisco strongly urges customers to immediately apply released hotfixes and update detection rules using the provided Snort SIDs while awaiting upcoming comprehensive security hardening updates.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Cisco FMC)
organisation
JAR
The web shell was then used to install a malicious JAR file named
cmd.jar
, which allowed them to execute commands on the server.
organisation
IP
The attackers collected hostnames, IP addresses, directory listings, Active Directory service account credentials, MySQL credentials, domain account information, computer lists, and hostname-to-IP address mappings for internal servers and infrastructure.
organisation
Active Directory
The attackers collected hostnames, IP addresses, directory listings, Active Directory service account credentials, MySQL credentials, domain account information, computer lists, and hostname-to-IP address mappings for internal servers and infrastructure.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Cisco Secure FMC
The vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management.
organisation
Cisco Security
The vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management.
organisation
Cisco
Cisco says it has already patched the cloud-hosted Security Cloud Control service.
organisation
Security Cloud Control
Cisco says it has already patched the cloud-hosted Security Cloud Control service.
organisation
Static Credential
Details are outlined in the security advisories (Static Credential vulnerability, Authentication Bypass vulnerability), and Cisco strongly recommends customers immediately apply the available fixes," a Cisco spokesperson told BleepingComputer.
organisation
Authentication Bypass
Details are outlined in the security advisories (Static Credential vulnerability, Authentication Bypass vulnerability), and Cisco strongly recommends customers immediately apply the available fixes," a Cisco spokesperson told BleepingComputer.
organisation
the Cisco Technical Assistance Center
"Customers needing support should contact the Cisco Technical Assistance Center (TAC).
organisation
TAC
"Customers needing support should contact the Cisco Technical Assistance Center (TAC).
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
September 2026
Oracle released new security patches in September 2026 to address approximately 800 identified flaws.
Click on any entity below to view its context and source!
general_metric
800 flaws
Oracle patches 800-plus flaws
Oracle has
announced
the release of new security patches as part of its September 2026 Critical Security Patch Update (CSPU).
Tactical Metrics
Metrics
data_breach
127
Aws Credential Records
Click for context!
Post-compromise activity included exfiltration from a workstation associated with the Thai military and collection of 127 AWS credential records."
Metrics
infrastructure
Linux
Affected Product
"While it retains familiar Mirai-style botnet functionality, it stands out for its unusually broad capability set, including multiple Linux n-day local privilege escalation exploits, extensive persistence coverage across Linux and embedded environments, encrypted C2 communications, anti-analysis checks, and decoy traffic," Nozomi Networks
said
.
"Unlike the WatchGuard-focused samples documented in 2022, the 2026 variant runs on x86-64 Linux and uses generic System V (SysV) persistence rather than vendor-specific firmware modification," Sophos
said
.
"In this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process."
KATARU brute-forces Telnet access
An IoT malware dubbed KATARU has leveraged Telnet credential brute-forcing to break into Linux and embedded systems.
UAT-11823 ultimately deployed a variant of Cyclops Blink on compromised devices, a modular Linux malware family previously
attributed to the Russian Sandworm threat group
.
Metrics
infrastructure
Windows
Affected Product
Docro Hijacker (a Chrome backdoor that can bypass
modern integrity protections
), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a
previously unnamed cross-platform backdoor
that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS.
"In the observed intrusions, attackers deployed remote monitoring and management (RMM) tools for persistence and then encrypted files, dropped RESTORE_FILES.txt ransom notes, cleared Windows event logs, and disabled Windows recovery options.
One incident also included signs of Bring Your Own Vulnerable Driver (BYOVD); as well as a notable misspelling by the threat actors during the attack, which left them unable to clear the Windows Defender Event Log."
"It pairs a Go control server called VectraHub, with a Vue3 operator panel compiled into the binary, with a native C++ Windows implant.
"Casbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use of fake windows to facilitate fraudulent activities," Fortinet FortiGuard Labs
said
.
"In this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process."
KATARU brute-forces Telnet access
An IoT malware dubbed KATARU has leveraged Telnet credential brute-forcing to break into Linux and embedded systems.
The .NET RAT is designed for persistent and interactive control over compromised Windows systems.
Azalea RAT arrives in the form of a Windows shortcut that masquerades as a PDF document to trigger the execution of a first-stage loader, which then performs anti-analysis checks before extracting a DLL that's responsible for setting up Microsoft Defender exclusion paths and ultimately launching the RAT.
The AutoIT script is designed to decrypt the payload in memory and inject it into a Microsoft-signed Windows process.
Metrics
infrastructure
Macos
Affected Product
Docro Hijacker (a Chrome backdoor that can bypass
modern integrity protections
), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a
previously unnamed cross-platform backdoor
that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS.
Metrics
infrastructure
Cursor
Affected Product
"Amatera targets data associated with Cline and Continue, while Remus targets Claude, Cursor, and OpenCode," Gen Digital
said
.
Metrics
financial
99,528
November
Carter, who worked at the store from May 2018 to November 2019, has also been ordered to pay $99,528 in restitution.
Metrics
financial
12,700,000,000
December
Nearly $13B tied to suspected crypto scams
The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (
BSA
) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams
perpetrated by overseas scam centers
.
Metrics
infrastructure
23
Servers
"Callback logs independently confirmed command execution with root privileges on 23 servers.
Metrics
financial
2,000
Carter
Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap.
Metrics
infrastructure
11
Commercial Devices
"This vulnerability exists in ubiquitous nonlinear analog interfaces across the 11 commercial off-the-shelf devices we evaluated, allowing attackers to eavesdrop on headphone and landline audio, infer smart-fan speed and smart-lamp brightness, and recover other analog secrets that digital encryption and software defenses can hardly protect," the researchers
said
.
Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices.
Metrics
victims
70
Victims
The group has claimed
70 victims to date
.
Metrics
financial
35
Service
The service costs $35 per month and claims to support three models on its website ("luciferus[.]io").
Metrics
data_breach
445
Smb
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).” concludes the report.
Metrics
data_breach
135
Netbios
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).” concludes the report.
Intelligence Sources
BleepingComputer
2026-09-10
The Hacker News
2026-09-17
Security Affairs
2026-09-11
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Security Affairs
BleepingComputer
2026-09-09
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-18T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
110x
organisation
Identified Entity
APT
entity
31x
timeline
Temporal Reference
August 2026
date
12x
target region
Target Country
Hong Kong
country
12x
attribution
Attributing Entity
The Moscow Times
authority
11x
tactic
Cyber Operation Type
Espionage
tactic
8x
industry
Targeted Sector
Technology
sector
6x
tactic
MITRE ATT&CK Technique
T1592.001 - Hardware
technique
5x
source region
Origin Country
China
country
5x
malware
Malware Payload
Denis
tool
4x
infrastructure
Affected Product
Linux
software
3x
vulnerability
Exploited CVE
CVE-2026-59310
cve
2x
general metric
Incidents
1,900
incidents
2x
general metric
Cve-2026
20,079
cve-2026
2x
vulnerability
CVSS Score
10
score
Contextual Telemetry
Context Block
26 METRICS
target region
Target Region
LATAM
region
data breach
Aws Credential Records
127
aws credential records
general metric
Sep
17
sep
general metric
Palo Alto Networks Unit
42
palo alto networks unit
general metric
Flaws
800
flaws
financial
November
99,528
november
general metric
Bank Secrecy Act
33,904
bank secrecy act
financial
December
12,700,000,000
december
general metric
More New Stories
22
more new stories
general metric
Artifacts
230
artifacts
general metric
Unauthenticated Localai Instances
243
unauthenticated localai instances
infrastructure
Servers
23
servers
general metric
Bod
4
bod
financial
Carter
2,000
carter
infrastructure
Commercial Devices
11
commercial devices
victims
Victims
70
victims
general metric
Parameters
120,000,000,000
parameters
financial
Service
35
service
general metric
Ldpa
389
ldpa
general metric
Ldaps
636
ldaps
general metric
Kerberos
88
kerberos
data breach
Smb
445
smb
data breach
Netbios
135
netbios
general metric
Jul
23
jul
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.