Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES THREAT INTELLIGENCE VULNERABILITIES & THREATS NEWS 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022. Jai Vijayan,Contributing Writer September 14, 2026 4 Min Read SOURCE: RATPACK223 VIA GETTY IMAGES A likely Russian threat actor is deploying a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices by chaining two vulnerabilities in Cisco's Firewall Management Center (FMC) technology. In separate reports, Sophos and Cisco identified the malware as a new version of Cyclops Blink, a modular botnet and backdoor that US and UK government agencies have previously linked to Sandworm, a threat actor with ties to Russia's Main Intelligence Directorate (GRU). Two Separate Cisco FMC Vulnerabilities Cisco described the Cyclops Blinks activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software. One of the vulnerabilities is CVE-2026-20079, a maximum severity authentication bypass vulnerability that lets an unauthenticated remote attacker run arbitrary code on affected devices and gain root access to the underlying operating system. The second vulnerability, tracked as CVE-2026-20316, is a lower severity flaw with a 5.3 CVSS score that allows a remote attacker to log in with low privileges and then use other previous FMC vulnerabilities to escalate privileges. Related:Maximum Severity GitLab Flaw Puts Supply Chains at Risk Threat actors possibly tied to Sandworm are chaining the two flaws to first download a Netcat-based reverse shell and proxy tool on vulnerable FMC systems and then use that to deploy the new Cyclops Blink variant. Cisco released hotfixes for both bugs last week and "strongly advised" organizations using the affected technology to apply them immediately, citing evidence of exploit activity in the world. The company said it would release a broader, hardened release with fixes for the two new flaws and other internally discovered vulnerabilities in FMC later this week. "Given the in the wild abuse we strongly recommend that customers apply the referenced hotfixes as soon as possible, pending the hardening release," Cisco said. Cyclops Blink is malware that first surfaced in 2022 and initially targeted WatchGuard firewalls and, later, ASUS devices. Its core functions included beaconing information about infected devices to command-and-control (C2) servers, downloading and executing malicious files, and adding new modules to expand its capabilities. The malware could persist through reboots and legitimate firmware updates, making it difficult to remove. However, the FBI led a court-authorized operation in which it accessed victims' devices, copied the Cyclops Blink malware, and then removed it. A Significant Upgrade for Cyclops Blink The latest variant, according to Sophos, retains many of the original features while adding several new ones. The most significant change is that the malware now runs on 64-bit x86-64 Linux systems rather than the older 32-bit PowerPC architecture used by the original version. It also uses generic Linux persistence techniques instead of modifying vendor-specific firmware. Related:Threat Actor Generates 1M Personalized Fraud Emails in 3 Days The new Cyclops Blink variant adds active network scanning and packet-capture capabilities and expands its data-collection functions to include password hashes, process command lines, CPU information, and configuration data. These changes potentially make Cyclops Blink compatible with a broader range of Linux-based network appliances and give attackers a more powerful platform for reconnaissance and intelligence collection, Sophos said. "Generic SysV persistence in the 2026 Cyclops Blink samples removes the dependency on WatchGuard-specific firmware, while active network scanning and selective packet capture substantially expand the implant’s intelligence-collection capabilities," Sophos researchers wrote. "The discovery on Cisco FMC devices highlights the risk posed by compromised network-management infrastructure." Compromised network appliances and other edge devices can give attackers a privileged vantage point into the broader environment and allow them to observe traffic, conduct network probes, and launch additional attacks, the vendor noted. Related:Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain In addition to the new Cyclops Blink campaign, two other groups are actively exploiting CVE-2026-20079 and CVE-2026-20316. The first cluster, which Cisco Talos is tracking as UAT 12197, is exploiting CVE-2026-20079 to plant Web shells and a Java-based command execution tool to steal credentials. The other threat cluster, UAT 11988, is exploiting CVE-2026-20316 to distribute Qilin ransomware. Sophos attributed the new Cyclops Blink campaign with high confidence to Russia-nexus actors and has moderate confidence it is associated with Sandworm, which the vendor tracks as Iron Viking. "The lower confidence in the threat group attribution reflects the absence of conclusive evidence directly linking IRON VIKING to the observed 2026 deployments," the researchers wrote. Sandworm is a Russian state-sponsored hacking group known for both espionage and destructive cyber operations. The group has been linked to some of the most consequential cyberattacks of the past decade, including attacks that disrupted Ukraine’s power grid and the NotPetya outbreak. More recently, Sandworm has expanded its use of vulnerabilities in Internet-facing infrastructure to gain access to organizations in Ukraine and elsewhere, while continuing to target critical infrastructure and other strategically important organizations. About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Cybersecurity Outlook 2027 Threat Exposure Analytics: Measuring and Communicating Security Risk Benchmark Scores Are a False Flag Building an Effective Red Team: Beyond Penetration Testing How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Operation DoppelBrand: Weaponizing Fortune 500 Brands by Elizabeth Montalbano FEB 16, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBERATTACKS & DATA BREACHES OpenAI Agents Took Over Wiki Site Before Hugging Face Attack byNate Nelson SEP 8, 2026 7 MIN READ APPLICATION SECURITY Mythos Vulnerability Firehose Hits a Human Bottleneck byJai Vijayan SEP 9, 2026 4 MIN READ VULNERABILITIES & THREATS Patch Tuesday Sets Another Record With 974 CVEs byJai Vijayan SEP 8, 2026 5 MIN READ Want more Dark Reading stories in your Google search results? HOW ORGANIZATIONS ARE MANAGING INCIDENT RESPONSE Nearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report. DOWNLOAD NOW NOVEMBER 12, 2026 | VIRTUAL What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI SAVE YOUR SPOT Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network t