ZeroHour

Search: “edr”

8 stories

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco Talos confirms ransomware and state-sponsored groups exploited CVE-2026-20079 and CVE-2026-20316 in Secure Firewall Management Center, deploying Qilin ransomware and Cyclops Blink.

Cisco Talos identified three threat clusters (UAT-12197, UAT-11823, UAT-11988) exploiting CVE-2026-20079, a CVSS 10.0 authentication bypass, and CVE-2026-20316, a CVSS 5.3 static-credential flaw, in Cisco Secure Firewall Management Center. Qilin affiliates used static credentials for reconnaissance and deployed Qilin ransomware; a Sandworm-linked cluster deployed a Cyclops Blink backdoor via a malicious license.tmp file; a third cluster stole credentials through a JSP web shell. Cisco has released hotfixes and urges immediate installation, with broader patches expected next week.

BleepingComputerupdated · 2d agofirst · 6d agoExploit / PoC in the wild 11 sourcesCVE-2026-20079CVE-2026-20316

Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank

Researcher Chaotic Eclipse released FalconFlank, a PoC zero-day privilege escalation exploit against CrowdStrike Falcon's Microsoft Office macro removal feature.

Security researcher Chaotic Eclipse (also known as Nightmare Eclipse) published FalconFlank, a proof-of-concept zero-day exploit for a privilege escalation flaw in CrowdStrike Falcon Sensor. It abuses the Microsoft Office file malicious macro removal remediation feature, which runs with high privileges, and works on fully updated Windows 11 25H2 and Windows Server 2025 with Falcon Phase 3 Optimal Protection. CrowdStrike says it is investigating and advises customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy. The same researcher recently released zero-day PoCs against Kaspersky Endpoint Security (HardBreacher) and Avast Antivirus (PrettyPrague), the latter dumping the SAM database for a SYSTEM shell.

Security Affairs · 7d agoExploit / PoC1· 1 read

Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity

Huntress observed rogue ScreenConnect deployments with worm-like VBScript propagation across unrelated organizations, prompting a ConnectWise advisory on file transfer behavior.

Huntress identified multiple incidents in late August 2026 where social engineering led to rogue ScreenConnect remote access clients deployed on victim machines, which then spawned wscript.exe to run four VBScript payloads (1.vbs through 4.vbs) for profiling, telemetry collection, and persistence via a WindowsServiceHost Run key. Modified ScreenConnect clients propagated the VBScript chain to connected endpoints, creating worm-like spread. ConnectWise published an advisory on September 3, 2026, confirming an issue affecting file transfer behavior in both cloud and on-premises ScreenConnect deployments, with a CVE and fix expected within the week; partners were advised to review and disable TransferFiles permissions in the interim.

Huntress · 13d agoExploit / PoC in the wild1

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able shipped a second N-central hotfix as attackers actively exploit authentication bypass CVE-2026-18577, attributed to ransomware group Storm-1175.

N-able released Hotfix 2 (N-central 2026.3.1.10) to counter ongoing exploitation of CVE-2026-18577, an authentication bypass that evades the patch for the earlier CVE-2026-18556; exploitation was first detected on August 1, 2026. Post-exploitation includes using the Take Control feature to reach managed endpoints, registering a Cloudflare tunnel service for persistence, creating a 'veeam' domain account, resetting admin passwords, and disabling Microsoft and Sophos security tooling. Microsoft analysts link the activity to Storm-1175, which now deploys a new StormEncryptor ransomware strain instead of Medusa, often reaching data exfiltration and ransomware within days. Sophos and Huntress expanded the IOCs and warned that partners who patched late should treat environments as potentially compromised.

Help Net Security · Aug 12, 2026Exploit / PoC in the wildCVE-2026-18577CVE-2026-185561