Date: 09/10/2026
Severity: High
Summary
Active exploitation of Cisco Secure Firewall Management Center (FMC) vulnerabilities CVE-2026-20079 and CVE-2026-20316, enabling authentication bypass, unauthorized access, and privilege escalation. Threat clusters deployed web shells, reverse shells, proxy tools, Cyclops Blink, and credential-harvesting capabilities. A separate ransomware operation used living-off-the-land (LOTL) techniques, network reconnaissance, tunneling, credential theft, and ultimately deployed Qilin ransomware.
Indicators of Compromise (IOC) List
IP Address | 43.204.2.142 89.34.96.56 208.123.119.215 104.218.165.253 91.214.78.118 |
Hash | B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d
Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e
6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | dstipaddress IN ("43.204.2.142","104.218.165.253","89.34.96.56","208.123.119.215","91.214.78.118") or srcipaddress IN ("43.204.2.142","104.218.165.253","89.34.96.56","208.123.119.215","91.214.78.118") |
Detection Query 2 : | sha256hash IN ("B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d","6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461","Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e")
|
Reference:
https://blog.talosintelligence.com/fmc-ongoing-exploitation/