September 12, 2026
- Cisco tied exploited FMC flaws to credential theft, a Cyclops Blink variant, and Qilin ransomware. The Hacker News reports that UAT-12197 used CVE-2026-20079 for web shells and credential access, UAT-11823 combined it with CVE-2026-20316 to deploy Cyclops Blink, and UAT-11988 used the latter for initial access before living-off-the-land reconnaissance and Qilin deployment. CISA’s September 12 patch deadline for U.S. federal civilian agencies is now in effect (earlier coverage).
· Vulnerabilities & Active Exploitation
in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack
September 11, 2026
- Cisco Talos has now split the Secure FMC exploitation into three post-compromise clusters (UAT-12197, UAT-11823, UAT-11988), with Qilin ransomware affiliates entering via the static-credential flaw CVE-2026-20316 and pivoting with a Python SOCKS5 proxy, reverse SSH and forwarded LDAP/Kerberos/SMB/WinRM; Cyclops Blink turned up in another cluster. Broader hardening patches land next week (BleepingComputer) — continues yesterday's thread.
· Exploitation in the Wild
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
September 10, 2026
- Cisco Secure Firewall Management Center: Talos is tracking active exploitation of CVE-2026-20079 (CVSS 10.0, unauthenticated auth bypass to root) and CVE-2026-20316 (5.3, low-privileged login). Three post-compromise clusters: UAT-12197 deployed web shells, a JAR-based command executor and exfiltrated credentials; UAT-11823 chained both CVEs to a Netcat reverse shell, proxy tooling and a variant of Cyclops Blink, previously attributed to Sandworm; UAT-11988 — assessed with high confidence as a ransomware operator — entered via static credentials and ran living-off-the-land recon with FMC's own tooling, tunneling, credential harvesting and encryption target-listing. Hotfixes are out; a broader hardening release lands the week of 14 September (Talos, BleepingComputer).
· Exploited in the Wild
in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon
July 31, 2026
- Cisco Secure Firewall Management Center zero-day CVE-2026-20316 was added to CISA's KEV catalog following reports of active exploitation; the static-credential flaw lets an unauthenticated remote attacker log in and access sensitive data (The Hacker News) — now confirmed exploited since earlier coverage.
· Vulnerabilities & Exploits
in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests