CYBER DELTA FORCESearch

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

A likely Russian threat actor is deploying a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices by chaining two vulnerabilities in Cisco's Firewall Management Center (FMC) technology.

CDF News DeskDark Reading15 Sept 2026, 3:07 am
CDF REPORT

A likely Russian threat actor is deploying a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices by chaining two vulnerabilities in Cisco's Firewall Management Center (FMC) technology. In separate reports, Sophos and Cisco identified the malware as a new version of Cyclops Blink, a modular botnet and backdoor that US and UK government agencies have previously linked to Sandworm, a threat actor with ties to Russia's Main Intelligence Directorate (GRU). Cisco described the Cyclops Blinks activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software. One of the vulnerabilities is CVE-2026-20079 , a maximum severity authentication bypass vulnerability that lets an unauthenticated remote attacker run arbitrary code on affected devices and gain root access to the underlying operating system.

The first cluster, which Cisco Talos is tracking as UAT 12197, is exploiting CVE-2026-20079 to plant Web shells and a Java-based command execution tool to steal credentials. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.

These changes potentially make Cyclops Blink compatible with a broader range of Linux-based network appliances and give attackers a more powerful platform for reconnaissance and intelligence collection, Sophos said. The other threat cluster, UAT 11988, is exploiting CVE-2026-20316 to distribute Qilin ransomware.

What changed

Cisco released hotfixes for both bugs last week and "strongly advised" organizations using the affected technology to apply them immediately, citing evidence of exploit activity in the world.

However, the FBI led a court-authorized operation in which it accessed victims' devices, copied the Cyclops Blink malware, and then removed it.

Related: Threat Actor Generates 1M Personalized Fraud Emails in 3 Days The new Cyclops Blink variant adds active network scanning and packet-capture capabilities and expands its data-collection functions to include password hashes, process command lines, CPU information, and configuration data.

"Generic SysV persistence in the 2026 Cyclops Blink samples removes the dependency on WatchGuard-specific firmware, while active network scanning and selective packet capture substantially expand the implant’s intelligence-collection capabilities," Sophos researchers wrote.

Related: Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain In addition to the new Cyclops Blink campaign, two other groups are actively exploiting CVE-2026-20079 and CVE-2026-20316.

Sophos attributed the new Cyclops Blink campaign with high confidence to Russia-nexus actors and has moderate confidence it is associated with Sandworm, which the vendor tracks as Iron Viking.

Who is affected

The company said it would release a broader, hardened release with fixes for the two new flaws and other internally discovered vulnerabilities in FMC later this week.

"Given the in the wild abuse we strongly recommend that customers apply the referenced hotfixes as soon as possible, pending the hardening release," Cisco said.

Cyclops Blink is malware that first surfaced in 2022 and initially targeted WatchGuard firewalls and, later, ASUS devices.

"The discovery on Cisco FMC devices highlights the risk posed by compromised network-management infrastructure." Compromised network appliances and other edge devices can give attackers a privileged vantage point into the broader environment and allow them to observe traffic, conduct network probes, and launch additional attacks, the vendor noted.

More recently, Sandworm has expanded its use of vulnerabilities in Internet-facing infrastructure to gain access to organizations in Ukraine and elsewhere, while continuing to target critical infrastructure and other strategically important organizations.

Why this matters

The first cluster, which Cisco Talos is tracking as UAT 12197, is exploiting CVE-2026-20079 to plant Web shells and a Java-based command execution tool to steal credentials.

His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.

The technical picture

These changes potentially make Cyclops Blink compatible with a broader range of Linux-based network appliances and give attackers a more powerful platform for reconnaissance and intelligence collection, Sophos said.

The other threat cluster, UAT 11988, is exploiting CVE-2026-20316 to distribute Qilin ransomware.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

MORE IN VULNERABILITIES

More cybersecurity reporting

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 ReleasesSecurityWeek · 15 Sept 2026, 4:36 pm4 in 5 Singapore Business Websites Have WordPress VulnerabilitiesThe Cyber Express · 15 Sept 2026, 1:53 pmCisco Secure Email Gateway zero-day exploited to gain root command executionThe Hacker News · 15 Sept 2026, 11:41 amHomebrew 7.0.0 gets built-in GUI, better security controlsBleepingComputer · 15 Sept 2026, 1:21 am