Cisco FMC Vulnerability Exploited by State Hackers and Ransomware Operators
Cisco has issued a warning about a critical vulnerability in its Secure Firewall Management Center (FMC) that is being actively exploited by threat actors. The bug, which was disclosed and patched earlier this year, allows attackers to remotely bypass authentication and gain root access to affected systems.
The Cisco Talos threat intelligence team said it is tracking three clusters of attacks, including suspected Russian state hackers and a Qilin ransomware operator. One cluster used the vulnerability to plant a malicious web shell, while another deployed Cyclops Blink malware for persistence and data theft.
Cisco released security updates in March to address the vulnerability, but the company strongly recommends that customers upgrade to a fixed software release to remediate it. The US Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities (KEV) catalog, setting a 3-day deadline for federal agencies to apply mitigations.