Download Privacy Needle App

Type to search

Cybersecurity

Sandworm Linked to Cisco Vulnerability Exploitation and Cyclops Blink Deployment

Share

Threat actors likely tied to the Russian state-sponsored group Sandworm are exploiting vulnerabilities in Cisco Firewall Management Center (FMC) software to deploy an upgraded version of the Cyclops Blink botnet.

The campaign involves chaining two specific flaws in Cisco’s Secure FMC software to gain control over network management infrastructure. The first is CVE-2026-20079, a maximum severity authentication bypass vulnerability that allows unauthenticated remote attackers to run arbitrary code and gain root access. The second is CVE-2026-20316, a lower severity flaw that facilitates privilege escalation.

Attackers use these vulnerabilities to download a Netcat-based reverse shell and proxy tool, which provides the foundation for deploying the Cyclops Blink malware variant.

Upgraded Malware Capabilities

Sophos researchers identified the new variant as a significant evolution of the original Cyclops Blink, which first appeared in 2022. The updated malware has transitioned from the older 32-bit PowerPC architecture to 64-bit x86-64 Linux systems.

The new version also employs generic Linux persistence techniques, such as SysV persistence, rather than modifying vendor-specific firmware. This change makes the malware compatible with a wider range of Linux-based network appliances. Additionally, the implant has expanded its intelligence-gathering capabilities to include active network scanning, selective packet capture, and the collection of password hashes, process command lines, and configuration data.

Security researchers at Sophos noted that the discovery on Cisco FMC devices highlights the heightened risk posed when network-management infrastructure is compromised, as it provides attackers with a privileged vantage point to observe traffic and probe the broader environment.

Wider Exploitation of Cisco Flaws

Cisco Talos is tracking two other distinct threat clusters exploiting these same vulnerabilities for different purposes. One cluster, identified as UAT 12197, is using the authentication bypass flaw to plant web shells and Java-based command execution tools to steal credentials. Another cluster, UAT 11988, is leveraging the privilege escalation flaw to distribute Qilin ransomware.

Mitigation and Vendor Response

Cisco has released hotfixes for both vulnerabilities and has strongly advised organisations using the affected technology to apply them immediately. The company stated it would also release a broader, hardened software release containing fixes for these flaws and other internally discovered vulnerabilities later this week.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.