‘Sandworm’ Chains Cisco Vulnerabilities to Deploy Cyclops Blink

Russian threat group Sandworm has been linked to a sophisticated malware implant that’s capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices. This upgraded version of the botnet malware, known as Cyclops Blink, is being deployed by chaining two vulnerabilities in Cisco’s Firewall Management Center (FMC) technology.

The malware, which has been previously linked to Sandworm, a threat actor with ties to Russia’s Main Intelligence Directorate (GRU), can now run on 64-bit x86-64 Linux systems, giving attackers a more powerful platform for reconnaissance and intelligence collection. The new variant retains many of the original features, including beaconing information about infected devices to command-and-control (C2) servers, downloading and executing malicious files, and adding new modules to expand its capabilities.

The two vulnerabilities being chained by Sandworm are in Cisco’s Secure FMC software. One is a maximum severity authentication bypass vulnerability, tracked as CVE-2026-20079, which allows an unauthenticated remote attacker to run arbitrary code on affected devices and gain root access to the underlying operating system. The other is a lower severity flaw with a 5.3 CVSS score that enables a remote attacker to log in with low privileges and then use other previous FMC vulnerabilities to escalate privileges.

Cisco has released hotfixes for both bugs, but warns that organizations using the affected technology should apply them immediately, citing evidence of exploit activity in the wild. The company plans to release a broader, hardened release with fixes for the two new flaws and other internally discovered vulnerabilities in FMC later this week.

The compromised network appliances and edge devices can give attackers a privileged vantage point into the broader environment, allowing them to observe traffic, conduct network probes, and launch additional attacks. This highlights the risk posed by compromised network-management infrastructure, which can be used as a launching pad for further exploits and attacks.

It’s worth noting that Cyclops Blink is not new malware; it first surfaced in 2022 and initially targeted WatchGuard firewalls and ASUS devices. However, this latest variant represents a significant upgrade, with active network scanning and packet-capture capabilities, and expanded data-collection functions that include password hashes, process command lines, CPU information, and configuration data.

The discovery of Cyclops Blink on Cisco FMC devices is a stark reminder of the importance of keeping software up to date and applying security patches in a timely manner. It’s also a warning sign that compromised network-management infrastructure can be used as a vector for further exploits and attacks, making it essential for organizations to regularly monitor their networks for signs of suspicious activity and take swift action to contain and remediate any incidents.

In light of this development, cybersecurity professionals are advised to review their network management infrastructure, ensure all software is up to date, and implement robust monitoring and detection capabilities to identify potential threats. Additionally, organizations should consider implementing a regular patching schedule for critical systems, including network appliances and edge devices, to minimize the risk of exploitation.


Source: Dark Reading — 2026-09-14