<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Fmc - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/fmc/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 09 Sep 2026 18:47:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/fmc/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Active Exploitation of Cisco Secure Firewall Management Center</title><link>https://feed.craftedsignal.io/briefs/2026-09-cisco-fmc-exploitation/</link><pubDate>Wed, 09 Sep 2026 18:47:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cisco-fmc-exploitation/</guid><description>Multiple threat actors, including state-sponsored groups and ransomware operators, are actively exploiting authentication bypass (CVE-2026-20079) and static credential (CVE-2026-20316) vulnerabilities in Cisco Secure Firewall Management Center to achieve root-level code execution and deploy malware.</description><content:encoded><![CDATA[<p>Cisco Talos is actively tracking the exploitation of multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) software. Threat actors are chaining CVE-2026-20079, a critical (CVSS 10.0) authentication bypass vulnerability, and CVE-2026-20316, which involves static credentials, to gain initial access and perform lateral movement. Talos has identified three distinct clusters of malicious activity. Cluster UAT-12197 utilizes CVE-2026-20079 to deploy JSP web shells and custom Java-based command executors for credential exfiltration. Cluster UAT-11823, identified as an APT with ties to Sandworm, uses these vulnerabilities to deploy Cyclops Blink malware via a malicious Makeself package. Cluster UAT-11988, assessed as a Qilin ransomware operator, uses static credentials for initial access followed by living-off-the-land (LOTL) techniques to conduct reconnaissance, deploy tunneling tools, and execute ransomware. Defenders must prioritize patching these vulnerabilities, as multiple groups are currently exploiting these flaws in the wild.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial Access: Attackers bypass authentication via CVE-2026-20079 or utilize static credentials (CVE-2026-20316) to access the FMC appliance.</li>
<li>Persistence: Attackers place malicious JSP web shells in the CSM Tomcat webroot directory or modify system startup scripts (e.g., /etc/init.d/) to maintain access.</li>
<li>Execution: Attackers abuse the legitimate package_info.pl utility to execute malicious files (e.g., license.tmp) or custom JAR files (e.g., cmd.jar) with root privileges.</li>
<li>Privilege Escalation: Exploitation of system utilities allows actors to transition from initial low-privileged access to root-level command execution on the underlying OS.</li>
<li>Discovery: Attackers perform system and network reconnaissance, including directory listing, credential harvesting via OmniQuery.pl, and internal database queries.</li>
<li>Command and Control: Deployment of Netcat-based reverse shells and SOCKS proxy/reverse-SSH tunneling tools to maintain communication with actor infrastructure.</li>
<li>Impact: Final stages include exfiltration of configurations, deployment of modular implants like Cyclops Blink, or deployment of Qilin ransomware to target endpoints.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to gain full administrative control over the FMC appliance. Observed impacts include the exfiltration of sensitive configuration data, deployment of modular botnet malware, and large-scale ransomware encryption of downstream enterprise networks.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Apply the security patches provided by Cisco for CVE-2026-20079 and CVE-2026-20316 immediately.</li>
<li>Implement monitoring for unauthorized files in the CSM Tomcat webroot directory.</li>
<li>Audit the use of system-level utilities like package_info.pl and OmniQuery.pl for anomalous command-line arguments.</li>
<li>Block communication with the known C2 IP 208.123.119.215 at the network perimeter.</li>
<li>Monitor for processes spawning unexpected shells or network utilities such as nc (Netcat).</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>cisco</category><category>fmc</category><category>exploitation</category><category>cve-2026-20079</category><category>cve-2026-20316</category><category>ransomware</category><category>apt</category></item></channel></rss>