Cyclops Blink deployed on compromised Cisco FMC devices
Malware Activity
Summary
Hide ▲
Show ▼
A Cyclops Blink variant was deployed on compromised Cisco Secure Firewall Management Center (FMC) devices, giving attackers a persistent backdoor with credential theft and network sniffing capability. The malware activity was tied to the UAT-11823 intrusion cluster and followed earlier access to the management appliances. The payload adds post-compromise control on a security-management platform that can expose internal credentials and traffic.
Related Happenings
Cisco Secure FMC static credential flaw actively exploited (CVE-2026-20316)
Vulnerability
H score51
First: 30.07.2026 00:35
Last: 30.07.2026 00:35
Sources 1
How related:
The threat actor accessed an FMC device using static credentials associated with CVE-2026-20316, then abused legitimate built-in FMC tools to perform reconnaissance of the victim's network.
About this happening:
Cisco Talos says CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) were exploited by three clusters tied to ransomware and...
Cisco Secure FMC static credential flaw actively exploited (CVE-2026-20316)
VulnerabilityHow related: The threat actor accessed an FMC device using static credentials associated with CVE-2026-20316, then abused legitimate built-in FMC tools to perform reconnaissance of the victim's network.
About this happening: Cisco Talos says CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) were exploited by three clusters tied to ransomware and...
BPFDoor Linux backdoor with HTTPS-hidden trigger packets
Malware Activity
H score23
First: 26.03.2026 19:40
Last: 26.03.2026 19:40
Sources 1
About this happening:
A newly disclosed BPFDoor variant is hiding trigger packets inside HTTPS traffic and using ICMP between infected hosts, making the Linux backdoor harder to detect...
BPFDoor Linux backdoor with HTTPS-hidden trigger packets
Malware ActivityAbout this happening: A newly disclosed BPFDoor variant is hiding trigger packets inside HTTPS traffic and using ICMP between infected hosts, making the Linux backdoor harder to detect...
Red Menshen telecom espionage campaign
Campaign
H score33
First: 26.03.2026 19:40
Last: 26.03.2026 19:40
Sources 1
About this happening:
A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...
Red Menshen telecom espionage campaign
CampaignAbout this happening: A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...
Timeline
-
10.09.2026 18:43 2 articles · 2h ago
Cyclops Blink is deployed on compromised Cisco FMC devices
Technical Analysis UpdateCisco Talos linked UAT-11823 to a variant of Cyclops Blink deployed on compromised Cisco Secure Firewall Management Center devices, describing the malware as a modular Linux backdoor that provides persistent access, credential theft, and network traffic sniffing. Talos also said the same cluster used a Netcat-based reverse shell, collected configuration data, and exploited FMC vulnerabilities during the intrusion activity.
Show sources
- Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers — www.bleepingcomputer.com — 10.09.2026 18:43
- Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers — www.bleepingcomputer.com — 10.09.2026 18:43