HighRansomwareGlobal

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Reported by The Hacker News · Sep 11, 2026 6:19 AM
Automated brief: This page adds defensive context to a third-party headline. Verify facts, scope, affected versions, indicators, and attribution in the original source.

What is being reported

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.

Why defenders should review it

Current threat reporting can affect exposure management, detection priorities, third-party risk, and incident readiness. Relevance depends on your assets, geography, industry, and control environment.

Defensive review checklist

  1. Verify the report with the original publisher and identify whether affected products or services exist in your environment.
  2. Check vendor advisories, versions, exposure, compensating controls, and patch or mitigation status.
  3. Review identity logs, strengthen phishing-resistant MFA, revoke suspicious sessions, and notify users with specific indicators.
  4. Hunt for published indicators, isolate suspected systems, preserve evidence, and verify recoverable offline backups.

Evidence and attribution

Raven Academy has not independently validated this event. Treat attribution, victim counts, exploit status, and impact as claims from the named publisher until corroborated.

Read original sourceBack to News