daily cyber × ai intelligence

index

tagged

[cyclops-blink]

2 editions · 2 items

September 12, 2026

  • Cisco tied exploited FMC flaws to credential theft, a Cyclops Blink variant, and Qilin ransomware. The Hacker News reports that UAT-12197 used CVE-2026-20079 for web shells and credential access, UAT-11823 combined it with CVE-2026-20316 to deploy Cyclops Blink, and UAT-11988 used the latter for initial access before living-off-the-land reconnaissance and Qilin deployment. CISA’s September 12 patch deadline for U.S. federal civilian agencies is now in effect (earlier coverage). · Vulnerabilities & Active Exploitation

in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack

September 10, 2026

  • Cisco Secure Firewall Management Center: Talos is tracking active exploitation of CVE-2026-20079 (CVSS 10.0, unauthenticated auth bypass to root) and CVE-2026-20316 (5.3, low-privileged login). Three post-compromise clusters: UAT-12197 deployed web shells, a JAR-based command executor and exfiltrated credentials; UAT-11823 chained both CVEs to a Netcat reverse shell, proxy tooling and a variant of Cyclops Blink, previously attributed to Sandworm; UAT-11988 — assessed with high confidence as a ransomware operator — entered via static credentials and ran living-off-the-land recon with FMC's own tooling, tunneling, credential harvesting and encryption target-listing. Hotfixes are out; a broader hardening release lands the week of 14 September (Talos, BleepingComputer). · Exploited in the Wild

in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon