:

CISCO FIREWALL FLAWS EXPLOITED BY RANSOMWARE, STATE HACKERS

SECURITY DESK1 MIN READ
THU, SEP 10, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Cisco Talos has confirmed that two recently patched vulnerabilities in Secure Firewall Management Center (FMC) are being actively exploited by three separate threat groups linked to ransomware operations and state-sponsored attacks.

The vulnerabilities in Cisco's FMC platform—a critical management tool for enterprise firewall deployments—represent a significant security risk for organizations relying on the system to protect their networks. Cisco Talos identified exploitation activity from three distinct threat clusters, indicating the flaws have attracted attention from both financially motivated ransomware gangs and government-backed threat actors. The company has already released patches, but organizations running unpatched instances remain vulnerable. FMC manages Cisco Secure Firewall devices across enterprise networks, making it an attractive target for attackers seeking broad network access. Compromise of the management center could allow threat actors to bypass firewall protections across an entire organization's infrastructure. Cisco has not disclosed specific details about the vulnerabilities' severity or attack methods. Security teams managing Cisco firewalls are urged to prioritize patching these flaws immediately and review logs for signs of unauthorized access to their FMC instances.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A likely Russian-speaking threat actor deployed hundreds of AI agents to systematically exploit vulnerabilities in PaperCut NG/MF servers worldwide. The coordinated campaign successfully compromised 395 organizations across multiple sectors.

JUST NOWAI Desk

ID verification company IDScan confirmed a major data breach compromising over 150 million driver's licenses and government-issued identity documents. The stolen data includes full names and personal identification information.

3H AGOSecurity Desk

Clearview AI is testing InquiryIQ, a prototype that uses xAI's Grok model to help law enforcement surface associates, social accounts, and personal information about individuals identified through Clearview's facial recognition database.

6H AGOAI Desk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a critical remote code execution vulnerability in WatchGuard Firebox firewalls. The flaw was previously flagged as under active exploitation in December.

7H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.