Russian Threat Actor Deploys Sophisticated Malware via Chained Cisco Flaws
A sophisticated malware implant is being deployed by a likely Russian threat actor, capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices. The malware, known as Cyclops Blink, is being installed by chaining two vulnerabilities in Cisco's Firewall Management Center (FMC) technology.
The FMC vulnerabilities, tracked as CVE-2026-20079 and CVE-2026-20316, allow an unauthenticated remote attacker to run arbitrary code on affected devices and gain root access to the underlying operating system. The threat actor is using these flaws to first download a Netcat-based reverse shell and proxy tool on vulnerable FMC systems and then use that to deploy the new Cyclops Blink variant.
Cisco has released hotfixes for both bugs, strongly advising organizations using the affected technology to apply them immediately, citing evidence of exploit activity in the wild. The company will release a broader, hardened release with fixes for the two new flaws and other internally discovered vulnerabilities in FMC later this week.
The latest variant of Cyclops Blink retains many of its original features while adding several new ones, including active network scanning and packet-capture capabilities, and expands its data-collection functions to include password hashes, process command lines, CPU information, and configuration data. This potentially makes Cyclops Blink compatible with a broader range of Linux-based network appliances and gives attackers a more powerful platform for reconnaissance and intelligence collection.