INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Self-Rewriting Agents Exploit Critical Cisco FMC Flaw

| 2026-09-17 17:32 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A sophisticated cyber threat landscape is unfolding, with multiple incidents and groups exploiting vulnerabilities to wreak havoc. The Chinese Advanced Persistent Threat (APT) has been found to be targeting the flaw in various countries' critical infrastructure, while a new class of electromagnetic side-channel attacks called InjectEave has demonstrated its potential for leaking sensitive information from external RF signals. Researchers have also identified several high-profile incidents involving Russia's Black Axe cybercrime syndicate, including wire fraud and money laundering charges against alleged leaders extradited to the US. These cases highlight the ever-evolving nature of modern cybersecurity threats, requiring swift action and effective countermeasures to protect against these emerging risks.
Technical Mitigations AI-generated
* Use secure authentication mechanisms, such as multi-factor authentication (MFA), to prevent unauthorized access to systems and data. * Regularly update and patch software and operating systems to ensure that known vulnerabilities are addressed before they can be exploited by attackers. * Implement a robust firewall configuration to block suspicious traffic and prevent unauthorized access to networks and systems. * Use encryption to protect sensitive data both in transit (e.g., HTTPS) and at rest (e.g., encrypted storage). * Conduct regular security audits and vulnerability assessments to identify potential weaknesses and address them before they can be exploited by attackers.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

lu•••••.io
RE•••••.txt
so•••••.py
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CasbaneiroCasbaneiroAmadeyAmadeyCyclops BlinkCyclops BlinkQilinQilin CVE-2026-20079CVE-2026-20079 CVE-2026-20316CVE-2026-20316 CVE-2026-59310CVE-2026-59310
Target & Sectors
DACH DACH NORTH_AMERICA NORTH_AMERICA LATAM LATAM cryptocurrencycryptocurrency financefinance governmentgovernment manufacturingmanufacturing retailretail technologytechnology
Incident Timeline
‎at least August 2022
Vectra, a rebranded Vecty company, exploited a Cisco FMC critical flaw in ransomware attacks targeting at least August 2022.
organisation Vectra
‎September 8, 2023
Threat actors exploited a previously unknown critical Cisco FMC flaw to gain unauthorized access and launch ransomware attacks on targeted organizations.
‎between September 8, 2023
Threat actors used a Cisco FMC flaw to target suspected digital asset investment scams.
organisation The U.S. Department
organisation Treasury
organisation Financial Crimes Enforcement Network
general_metric 33,904 Bank Secrecy Act
financial $12.7 December
‎May 2025
Threat actors exploited a critical Cisco FMC flaw in the targeted systems.
source_region Cyprus
‎July 2025
Threat actors exploited a critical Cisco FMC flaw to distribute the OfferLoader custom loader between July 2025 and April 2026.
organisation OfferLoader
‎November 2025
Threat actors exploited a critical Cisco FMC flaw to target Sergei Filimonov and Denis Obrezko.
source_region Russian Federation
source_region Thailand
tactic Espionage
malware Denis
‎December 2025
The Justice Department discovered a critical Cisco FMC flaw exploited in ransomware attacks.
organisation the Justice Department
‎December 31, 2025
Threat actors exploited a critical Cisco FMC flaw in ransomware attacks targeting overseas scam centers.
organisation The U.S. Department
organisation Treasury
organisation Financial Crimes Enforcement Network
general_metric 33,904 Bank Secrecy Act
financial $12.7 December
‎April 2026
Threat actors exploited a critical Cisco FMC flaw to target the ransomware attack chain, which delivered payloads via custom loader OfferLoader starting from July 2025.
organisation OfferLoader
‎June 2026
Threat actors used a Cisco FMC flaw to target entities in the U.S., Germany, and other countries.
industry Technology
target_region Germany
target_region Canada
target_region Australia
industry Manufacturing
industry Retail
organisation Zscaler ThreatLabz
‎July 23, weeks
The incident involved a critical Cisco FMC flaw that was exploited in ransomware attacks, with the vulnerability being publicly disclosed just weeks before Cisco announced it had been patched.
vulnerability CVE-2026-20079
‎July 23
Threat actors used Cisco's July 23 hot fix for CVE-2026-20079 to exploit the vulnerability.
vulnerability CVE-2026-20079
‎July 29, 2026
Threat actors exploited a critical Cisco FMC flaw to target the affected system.
organisation Cisco Secure Firewall Management Center
‎July 29
Threat actors exploited a Cisco FMC flaw, CVE-2026-20316, which was being actively targeted in ransomware attacks.
vulnerability CVE-2026-20316
organisation Secure FMC
general_metric 20316 CVE-2026
‎August 2026
Sophos detected a ransomware attack using Cyclops Blink on Cisco FMC devices in Latin America.
source_region China
source_region Germany
organisation APT
industry Legal
tactic Phishing
target_region LATAM
malware Casbaneiro
organisation PDF
tactic Botnet
malware Cyclops Blink
organisation Cisco FMC
organisation Sophos
organisation Cisco Firewall Management Center
organisation FMC
vulnerability CVE-2026-20079
‎August 28, 2026
Threat actors exploited a critical Cisco FMC flaw to target Searzhudin Aktulayev, 40.
source_region Cyprus
‎2026/09/09
Threat actors exploited CVE-2026-20079 in Cisco FMC systems to target Federal Civilian Executive Branch agencies.
vulnerability CVE-2026-20079
tactic T1588.006 - Vulnerabilities
general_metric 20079 CVE-2026
attribution KEV
attribution Known Exploited
attribution Federal Civilian Executive Branch
‎September 11, 2026
Threat actors used a critical Cisco FMC flaw to deploy Qilin ransomware.
tactic Ransomware
organisation Cisco FMC
malware Qilin
‎September 12, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
vulnerability CVE-2026-20079
attribution KEV
tactic T1588.006 - Vulnerabilities
general_metric 20079 CVE-2026
attribution Known Exploited
attribution Federal Civilian Executive Branch
‎2026/09/12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered Federal Civilian Executive Branch agencies to secure vulnerable Cisco FMC systems by September 12, 2026 due to a critical CVE-2026-20079 flaw.
vulnerability CVE-2026-20079
tactic T1588.006 - Vulnerabilities
general_metric 20079 CVE-2026
attribution KEV
attribution Known Exploited
attribution Federal Civilian Executive Branch
‎Sep 17, 2026
Threat actors exploited a previously unknown critical Cisco FMC flaw to gain unauthorized access and launch ransomware attacks on targeted organizations.
‎May 2018 to November 2019
Carter was ordered to pay $99,528 in restitution for a critical Cisco FMC flaw exploited in ransomware attacks that occurred between May 2018 and November 2019.
financial $99,528 November
‎2026/09/17
Threat actors used social media websites, online dating websites, and voice over internet protocol phone numbers to find victims in the United States.
organisation APT
organisation Sandworm APT
organisation RF
organisation the Hong Kong Polytechnic University
organisation InjectEave
infrastructure Linux
organisation Sandworm
data_breach 127 AWS credential records
organisation Black Axe
organisation Ploutus
organisation Gouveia-Aguilera
organisation ATM
organisation VectraRAT MaaS
organisation VectraRAT
infrastructure Windows
organisation The Spanish Data Protection Agency
organisation Settra
organisation MeshAgent
organisation Huntress
organisation Cynet
organisation SloppyRAT
organisation Makeself
organisation SSH
organisation AV
organisation Invoke-TheHash
organisation FMC
organisation Mirai
organisation Secure FMC
organisation ELF
organisation DNS
organisation HTTPS
organisation EDR
organisation WatchGuard
organisation HTA
organisation IoT
organisation DDoS
infrastructure Macos
organisation Chrome
organisation ARKTunnel
organisation WebSocket
organisation Insomnia
organisation RMM
organisation the Windows Defender Event Log
organisation VectraHub
organisation DLL
organisation Microsoft Defender
organisation Microsoft
organisation CVE-2026-20079
organisation CVSS
organisation JSP
organisation UAT-12197
organisation BleepingComputer
organisation Secure Firewall Management Center
infrastructure Cursor
organisation Claude
organisation Hacking News / Cybersecurity News
organisation CL-CRI-1171
organisation Palo Alto Networks Unit
organisation LocalAI
organisation MCP STDIO
organisation API
organisation ECS
organisation Irregular
organisation Fortra
organisation Security Research and Development
organisation SIM
organisation AT&T Store
organisation Mandiant
organisation EM
organisation Uncensored AI
organisation OptimusPrimero
organisation Telegram
organisation TCP
organisation MessagePack
organisation ClickFix
organisation MCP
organisation EtherHiding
organisation ThreatLabz
organisation XOR
organisation the U.S. Justice Department
organisation Royder Adrian Figuera-Perez
organisation Italo Lizandro Corrales-Carrillo
organisation the U.S. Federal Bureau of Investigation
organisation Court
infrastructure 23 servers
financial $2,000 Carter
infrastructure 11 commercial devices
victims 70 victims
financial $35 service
organisation SMB
organisation NETBIOS
organisation Cisco Secure Firewall Management Center
data_breach 445 SMB
data_breach 135 NETBIOS
organisation Snort
organisation SecurityAffairs
organisation JAR
organisation IP
organisation Active Directory
organisation NFL
organisation CHANEL
organisation Cisco Secure FMC
organisation Cisco Security
organisation Cisco
organisation Security Cloud Control
organisation Static Credential
organisation Authentication Bypass
organisation the Cisco Technical Assistance Center
organisation TAC
organisation The Blue Report 2026
‎September 2026
Oracle released new security patches in September 2026 to address approximately 800 identified flaws.
general_metric 800 flaws
Tactical Metrics
Metrics
data_breach
127
Aws Credential Records
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎Cursor
Affected Product
Metrics
financial
99,528
November
Metrics
financial
12,700,000,000
December
Metrics
infrastructure
23
Servers
Metrics
financial
2,000
Carter
Metrics
infrastructure
11
Commercial Devices
Metrics
victims
70
Victims
Metrics
financial
35
Service
Metrics
data_breach
445
Smb
Metrics
data_breach
135
Netbios