60
60
60
60
Week in review: Disrupted Cyclops Blink botnet, public software apps at risk, Patch Tuesday forecast
60
55
55
60
60
60
60
60
55
55
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups, including Qilin ransomware operators, exploit critical Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316 for root access, credential theft, and ransomware.
Cisco Talos identified three post-compromise clusters exploiting recently patched Cisco Secure Firewall Management Center flaws. UAT-12197 deploys JSP web shells and harvests credentials; UAT-11823 (with Sandworm-overlapping tooling) installs Cyclops Blink for persistence; UAT-11988 (Qilin) uses static credentials, extensive reconnaissance, SOCKS5 proxies, reverse-SSH tunnels, AV killers, and ransomware deployment. CISA added CVE-2026-20079 to the KEV catalog with a September 12, 2026 patch deadline for federal agencies; Cisco urges immediate hotfix application.
90
60
60
60
FBI Director Wray talks takedown operations, nation-state hackers, and growing threats in cyberspace
60
60
55
60
60
60
60
60
60
60
55
60
60
60
60
60
55
60
60
60