HIGHRansomware
Global

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

·Source: The Hacker News

Updated:

Executive Summary

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

Analysis

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

Indicators of Compromise (1)

CVE (1)
CVE-2026-20079
Source Attribution

Originally published by The Hacker News on Sep 11, 2026.

Related Threats

HIGHRansomware

Ukrainian Conti Ransomware Developer Gets 4 Years in US Prison

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ukrainian-conti-ransomware-developer-gets-4-years-in-us-prison-image_small-1-a-32805.jpg" align=right hspace=4><b>Lytvynenko Admitted Developing Malware and Stealing Data for Conti</b><br>A U.S. court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison after he admitted developing malware and stealing data for

Bank Info Security
HIGHRansomware

Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware

There&#8217;s an update to a previously reported case. From the Department of Justice, this press release: Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000... Source

DataBreaches.net
CRITICALZero Day

Metasploit Wrap Up: This One Goes to Sixteen!

This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Auth

CVE-2025-66516CVE-2025-54988
Rapid7