September 10, 2026
- Cisco Secure Firewall Management Center: Talos is tracking active exploitation of CVE-2026-20079 (CVSS 10.0, unauthenticated auth bypass to root) and CVE-2026-20316 (5.3, low-privileged login). Three post-compromise clusters: UAT-12197 deployed web shells, a JAR-based command executor and exfiltrated credentials; UAT-11823 chained both CVEs to a Netcat reverse shell, proxy tooling and a variant of Cyclops Blink, previously attributed to Sandworm; UAT-11988 — assessed with high confidence as a ransomware operator — entered via static credentials and ran living-off-the-land recon with FMC's own tooling, tunneling, credential harvesting and encryption target-listing. Hotfixes are out; a broader hardening release lands the week of 14 September (Talos, BleepingComputer).
· Exploited in the Wild
in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon
September 3, 2026
- Leaked Russian training materials map the pipeline from university recruitment to operational units including Sandworm — useful for understanding how consistent the tradecraft is across espionage, sabotage and influence tasking (Schneier on Security, SC World).
· Threat Activity
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion
August 29, 2026
- ESET documented GuardBreaker, an anti-EDR technique used by Russia-aligned UAC-0099 against a Ukrainian victim (@thegrugq), continuing a busy week for the group (earlier coverage). Separate analysis traces a UAC-0099 WSF lure through a LUNCHPOKE → BURNYBEAR → MATCHBOIL.V2 chain with claimed overlap into Sandworm activity (chain analysis).
· Threat Activity
in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
August 11, 2026
- CERT-UA warns of Sandworm subcluster UAC-0145 running fake-job social engineering against Ukrainian sysadmins. Posing as an IT firm (e.g. "ATLAS Business Group") on job boards, the actor studies a candidate's résumé before making contact — attribution ties to APT44/Seashell Blizzard (CERT-UA).
· Threat Activity
in Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework
July 17, 2026
- Sandworm is using a fake-CAPTCHA lure against Ukrainian victims — instead of verifying they're human, users are instructed to paste a malicious PowerShell command into Windows (The Record).
· Threat Activity
in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands