State-sponsored and crimeware actors actively exploit two Cisco FMC vulnerabilities (CVE-2026-20079, CVE-2026-20316) to deploy web shells, Cyclops Blink, and Qilin ransomware. Three threat clusters exploit CVE-2026-20079 (CVSS 10.0 auth bypass) and CVE-2026-20316 (low-priv login) on Cisco Secure FMC. UAT-12197 deploys web shells and credential stealers. UAT-11823 deploys Cyclops Blink via Netcat tunnels. UAT-11988 conducts Qilin ransomware operations.
Qilin Ransomware
5 posts
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities 31th August – Threat Intelligence Report - Check Point Research This weekly threat intelligence report covers multiple active breaches, AI-related threats, and critical vulnerability disclosures. PaperCut, ServiceNow, Vercel Next.js, and Ubiquiti all released patches for critical vulnerabilities, several rated CVSS 10.0, with PaperCut vulnerabilities actively exploited in the wild. Notable breaches include Manchester Airports Group (8.7 million records exposed), ATF (Qilin ransomware), Boston Scientific (operational disruption), and McKesson (ShinyHunters exfiltrated 1TB via Okta vishing). Threat actor activity includes expanded toolsets from Iran-linked Nimbus Manticore and China-linked QTFY infrastructure disruption by U.S. authorities.
Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware Arctic Wolf Labs investigated multiple intrusions during June 2026 where threat actors exploited CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to gain initial access and deploy Qilin ransomware. After establishing VPN sessions, attackers performed credential harvesting via LSASS dumping and NTDS extraction, moved laterally using PsExec and administrative shares, deployed multiple remote access tools for persistence, and executed enterprise-wide log clearing before ransomware deployment. The variability in post-exploitation tradecraft across intrusions is consistent with multiple affiliates operating under the Qilin RaaS umbrella sharing exploitation infrastructure.
June 2026 CVE Landscape Insikt Group identified 60 high-impact vulnerabilities in June 2026 (a 49% increase from May), with 23 listed in CISA's KEV catalog and 53 having public PoC exploits. The dominant theme was exploitation of externally reachable enterprise applications and appliances by multiple threat actors: StrikeShark chained 13 CVEs to deploy SharkLoader and Cobalt Strike, Lazarus exploited CVE-2025-55182 (React2Shell, CVSS 10.0) to deploy COPPERHEDGE and EtherRAT, APT36 targeted India via Microsoft Office/Windows CVEs, and Qilin ransomware was linked to Check Point gateway exploitation. 25 of the 60 vulnerabilities enabled RCE across 18 vendors, with CWE-22 (Path Traversal) being the most common flaw class.
Intelligence Center The Talos 2025 Year in Review highlights a significant shift towards attackers targeting identity infrastructure and network components to bypass MFA and gain privileged access. Key threats include widespread exploitation of React2Shell, supply chain attacks targeting CI/CD pipelines, and the dominance of Qilin ransomware.