daily cyber × ai intelligence

index

tagged

[sandworm]

5 editions · 5 items

September 10, 2026

  • Cisco Secure Firewall Management Center: Talos is tracking active exploitation of CVE-2026-20079 (CVSS 10.0, unauthenticated auth bypass to root) and CVE-2026-20316 (5.3, low-privileged login). Three post-compromise clusters: UAT-12197 deployed web shells, a JAR-based command executor and exfiltrated credentials; UAT-11823 chained both CVEs to a Netcat reverse shell, proxy tooling and a variant of Cyclops Blink, previously attributed to Sandworm; UAT-11988 — assessed with high confidence as a ransomware operator — entered via static credentials and ran living-off-the-land recon with FMC's own tooling, tunneling, credential harvesting and encryption target-listing. Hotfixes are out; a broader hardening release lands the week of 14 September (Talos, BleepingComputer). · Exploited in the Wild

in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon