Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cyclops Blink deployed on compromised Cisco FMC devices

Malware Activity
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

A Cyclops Blink variant was deployed on compromised Cisco Secure Firewall Management Center (FMC) devices, giving attackers a persistent backdoor with credential theft and network sniffing capability. The malware activity was tied to the UAT-11823 intrusion cluster and followed earlier access to the management appliances. The payload adds post-compromise control on a security-management platform that can expose internal credentials and traffic.

Related Happenings

Cisco Secure FMC static credential flaw actively exploited (CVE-2026-20316)

Vulnerability
H score51 First: 30.07.2026 00:35 Last: 30.07.2026 00:35 Sources 1

How related: The threat actor accessed an FMC device using static credentials associated with CVE-2026-20316, then abused legitimate built-in FMC tools to perform reconnaissance of the victim's network.

About this happening: Cisco Talos says CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) were exploited by three clusters tied to ransomware and...

BPFDoor Linux backdoor with HTTPS-hidden trigger packets

Malware Activity
H score23 First: 26.03.2026 19:40 Last: 26.03.2026 19:40 Sources 1

About this happening: A newly disclosed BPFDoor variant is hiding trigger packets inside HTTPS traffic and using ICMP between infected hosts, making the Linux backdoor harder to detect...

Red Menshen telecom espionage campaign

Campaign
H score33 First: 26.03.2026 19:40 Last: 26.03.2026 19:40 Sources 1

About this happening: A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...

Timeline

  1. 10.09.2026 18:43 2 articles · 2h ago

    Cyclops Blink is deployed on compromised Cisco FMC devices

    Technical Analysis Update

    Cisco Talos linked UAT-11823 to a variant of Cyclops Blink deployed on compromised Cisco Secure Firewall Management Center devices, describing the malware as a modular Linux backdoor that provides persistent access, credential theft, and network traffic sniffing. Talos also said the same cluster used a Netcat-based reverse shell, collected configuration data, and exploited FMC vulnerabilities during the intrusion activity.

    Show sources