Tag: cisco
-
Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero trust AI agents demand a different kind of security In this interview, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/13/week-in-review-linux-rootkit-deployed-on-f5-big-ip-apm-devices-cisco-fmc-bugs-exploited/
-
Cisco bestätigt Angriffe auf kritische FMC-Sicherheitslücke
Die Schwachstelle CVE-2026-20079 im Cisco Secure FMC hat den Höchstwert 10.0 und wird laut Cisco bereits aktiv ausgenutzt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/cisco-sicherheitsluecke
-
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Tags: access, authentication, cisco, control, credentials, cve, exploit, firewall, flaw, group, ransomware, threatThree threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run…
-
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Tags: attack, authentication, cisco, credentials, cve, exploit, firewall, flaw, ransomware, software, threat, vulnerabilityCisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass First seen on…
-
Cisco Firewall Bugs Let in Sandworm, Qilin
Cisco Observed 3 Distinct Intrusion Clusters Exploiting 1 or Both Flaws. Cisco says a nation-state actor and a Qilin ransomware operator are actively exploiting two Secure Firewall Management Center flaws to gain root or credential-based access, steal sensitive data, deploy Sandworm-linked malware and prepare networks for encryption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cisco-firewall-bugs-let-in-sandworm-qilin-a-32793
-
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cisco, citrix, cve, cybersecurity, exploit, flaw, fortinet, google, infrastructure, kev, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20079 (CVSS score of 10.0) is an authentication bypass issue. The flaw resides in Cisco Secure…
-
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
-
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
-
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
-
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
-
Daily OT Security News: September 10, 2026
Cisco FMC Flaw Added to CISA’s Known Exploited Vulnerabilities Catalog SecurityWeek reported that Cisco and CISA flagged active exploitation of CVE-2026-20079, a critical authentication-bypass vulnerability in Cisco Secure Firewall Management Center that can let a remote unauthenticated attacker execute malicious… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-10-2026/
-
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/cisco-fmc-exploited-cve-2026-20079-cve-2026-20316/
-
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
Tags: authentication, cisa, cisco, citrix, cve, cybersecurity, exploit, flaw, fortinet, infrastructure, kev, update, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.The vulnerabilities are listed below – CVE-2026-20079 (CVSS score: 10.0) – An authentication First seen…
-
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
-
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/fmc-ongoing-exploitation/
-
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim’s browser session. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/clickfix-moves-into-the-browser/
-
The Best DNS Security Solutions, Compared and Priced (2026)
DNS security delivers more blocked attacks per dollar than any other network control when you buy the right shape at the right tier. The value verdict: DNSFilter and SafeDNS own transparent per-user pricing for SMBs, Cloudflare Gateway starts free and scales to national infrastructure (it now runs the UK’s public-sector PDNS with Accenture), Cisco Umbrella…
-
The 12 Best Wireless / Wi-Fi Security Solutions, Compared and Priced
Best value overall: Ubiquiti. Published hardware pricing, no mandatory licensing, and WPA3 with VLAN segmentation included for organizations whose compliance requirements don’t demand enterprise wireless intrusion prevention. Best capability: HPE Aruba. Best management: Cisco Meraki and Juniper Mist. Best if you own the firewall: Fortinet, utilizing your existing FortiGate firewalls. The critical cost question in…
-
The 12 Best Secure Web Gateway (SWG) Solutions, Compared and Priced
Best value overall: Cloudflare. It publishes per-user pricing, offers a free tier that lets you test the model properly, and delivers from one of the largest edge networks in the world. Best capability: Zscaler and Netskope. Best if you already own it: Fortinet and Cisco Umbrella. Below, 12 gateways scored across five weighted criteria, a…
-
Cisco Fixed Critical RCE in Nexus 9000 Series Switches
Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges. Cisco’s Technical Assistance Center…
-
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.The Nexus vulnerability,…
-
Critical Cisco Nexus 9000 Flaw Allows Remote Root Code Execution
Cisco disclosed a critical Nexus 9000 flaw that can allow unauthenticated remote attackers to execute code as root on affected switches. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-cisco-nexus-9000-vulnerability/
-
Critical Cisco Nexus 9000 Flaw Allows Remote Root Code Execution
Cisco disclosed a critical Nexus 9000 flaw that can allow unauthenticated remote attackers to execute code as root on affected switches. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-cisco-nexus-9000-vulnerability/
-
Critical Cisco Nexus 9000 Flaw Lets Remote Attackers Execute Code as Root Without Authentication
Cisco has released security updates addressing a critical vulnerability in Nexus 9000 Series switches that could allow unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability, tracked as CVE-2026-20212, has a CVSS score of 9.8 and affects Nexus 9000 platforms that are equipped with Cisco Silicon One ASICs. Cisco Nexus 9000 Flaw…
-
China’s ‘Fire Ant’ campaign used compromised Cisco routers as platform for more attacks
A hacking operation dubbed Fire Ant “didn’t just compromise systems,” according to researchers. “It compromised the trust layer those systems depend on.” First seen on therecord.media Jump to article: therecord.media/router-hacks-fire-ant-group-china
-
China-Linked Hackers Turn Cisco Routers Into Covert Network Gateways
China-linked Fire Ant hackers compromised Cisco IOS XR routers, management hosts, and authentication systems to create covert paths into other networks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-fire-ant-hackers-cisco-ios-xr-routers/
-
Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure
China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Security firm Sygnia, which investigated the activity, said Fire Ant has remained active since it was first reported in 2025. The actor’s latest operations show…
-
State-linked actor targets Cisco routers for espionage
An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/state-actor-cisco-routers-China-espionage/829181/
-
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant’s new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/

