Sandworm's Cyclops Blink Is Back, On Your Cisco Firewall Manager. Our Harvester Had the PoC 32 Days Before CISA Listed It, and the File Path Cisco Published as the IOC Was in Our Feed on August 18.
CISA added fourteen vulnerabilities to the Known Exploited Vulnerabilities catalog between September 8 and 11. We ran every one of them against our exploit harvester, which watches GitHub for public proof-of-concept code and turns what it finds into detection rules. For ten of the fourteen we had nothing before the listing. For one we had a PoC the same day. For one we had it seven days early. And for one, Cisco Secure Firewall Management Center CVE-2026-20079, we had a weaponized PoC in the feed 32 days before CISA listed it, carrying the exact file path Cisco would later publish as the indicator of compromise.
That is the left-of-boom number, and it comes with an attribution that should get your attention: Cisco Talos believes one of the three clusters exploiting this bug is Sandworm, and the implant they are dropping on firewall managers is Cyclops Blink.
The timeline, with our timestamps beside theirs
March 4, 2026. Cisco publishes CVE-2026-20079 as a CVSS 10.0: an unauthenticated attacker sends crafted HTTP requests to the FMC web interface, bypasses authentication through an alternate path, and executes script files as root. It ships in a batch of 25 advisories and 48 vulnerabilities. We covered that batch on March 17 under the headline that two of them were CVSS 10.0 unauthenticated root on the firewall management console. This was one of the two.
July 23. The earliest log entry Cisco later associates with exploitation activity, per BleepingComputer's reading of the advisory. July 29. Cisco ships fixes for 20079 and discloses its sibling, CVE-2026-20316, a static credential in the same product, as actively exploited. We published on 20316 that evening.
August 8, 18:06 UTC. Our harvester picks up a public repository claiming a PoC for CVE-2026-20079 and emits three detection rules. August 18, 00:01 UTC. A second, different repository. This one the harvester grades weaponized: its endpoint list includes /var/tmp/license.tmp, a /dev/tcp reverse shell, and ncat. Five rules emitted. Both go into the STIX feed and the hashes and URL lists the same night.
August, date unspecified. Cisco PSIRT becomes aware of active exploitation of 20079.
September 9. Cisco confirms exploitation. CISA lists it with a three-day deadline. Talos publishes the campaign with indicators. The IOC Cisco tells you to grep your /var/log/messages for is a package_info.pl invocation against /var/tmp/license.tmp.
What the three clusters are doing
Talos names them by its internal designators and attributes two with stated low confidence.
UAT-12197, unattributed. Exploits 20079, plants a home.jsp web shell in the CSM Tomcat directory, and drops a JAR-based command executor to pull credentials off the box.
UAT-11823, which Talos believes is Sandworm. Gets in through either bug, modifies license.tmp to spawn a reverse shell, harvests firewall configurations, and installs Cyclops Blink. If that name is familiar, it should be: Cyclops Blink was the Sandworm botnet built on WatchGuard and ASUS routers that the FBI disrupted by court order in April 2022. Seeing it on a Cisco firewall management appliance four years later, with a NetCat reverse shell to four command-and-control addresses and a dedicated scanner for this specific CVE, is not a new tool. It is an old one with a new host.
UAT-11988, which Talos suspects is a Qilin ransomware operator. Logs in with the 20316 static credential, does reconnaissance, steals credentials, establishes persistence, deploys AV killers, and delivers ransomware. One attacker IP, in an AWS Mumbai range, a rented machine.
Where we stand, flat
The lead is real and it is narrower than the headline number. Our harvester does not see exploitation; it sees public exploit code. What it caught on August 8 was a repository claiming to be a PoC, and on August 18 a second one whose contents matched what a working exploit for this bug would need. We do not verify exploitability, and Cisco FMC is the product where, in January, we found a PoC repository that was a webshell in disguise. So the honest claim is: 32 days before the federal listing, the feed carried detection rules keyed on the paths this exploit uses, including the one Cisco later named as the IOC. That is a weaponization signal, not a sighting of the attackers.
The indicators themselves we did not have. None of the five Talos IPs were in our corpus before today. One of them, [91.214.78.118](https://analytics.dugganusa.com/stix/register?ref=ioc-click&q=91.214.78.118), sits in a /24 that Spamhaus DROP has listed and that we redistribute, so a defender consuming our IP blocklist was dropping that range already. That is block coverage, credited to Spamhaus. The other four and the three hashes are in the feed as of tonight under a campaign-specific source, attributed to their UAT cluster, with Talos as the reference and the Cyclops Blink family on the ones that carry it.
And our own edge saw nothing. Zero probes for /api/fmc_config, /help/about.cgi, license.tmp, or the privileged script handler across 7,280 honeypot captures. Our canaries are shaped like WordPress and .env files. Nobody looking for firewall managers has a reason to touch them. That is a gap in the instrument's shape, and it is why this post's lead comes from GitHub and not from the honeypot.
The other thirteen, so the one is honest
Cisco FMC is the outlier. Of the fourteen KEV additions this week, our harvester had a PoC before the listing for three: Cisco FMC at 32 days, Citrix NetScaler CVE-2026-19490 at seven days, and GitLab CVE-2026-85706 on the same day. It caught the Chromium V8 CVE-2026-87491 PoC three days after listing, and the Artifactory CVE-2026-82329 PoC one day after. For the two Windows bugs, both MikroTik RouterOS bugs, ScreenConnect, N-central, Magento, and the two remaining Artifactory bugs, it had nothing at all. Three of fourteen early is the measured rate, and it lines up with what we found in July when we ran the same comparison across 86 KEV entries: fifteen armed before CISA listed them. The harvester is a real instrument with a real hit rate, and the hit rate is not high. It is high enough that when it fires on a CVSS 10 in a firewall manager, you should patch that day.
If you run FMC
Hot fixes prevent future exploitation and do not remediate a compromised device; Cisco says so plainly. Grep /var/log/messages for package_info.pl with license.tmp. Check the CSM Tomcat webapps directory for home.jsp. Look for outbound connections from the FMC to the four UAT-11823 addresses, and for any login using the 20316 static account. If you find any of it, the box is not yours; call TAC and rebuild. The four IPs and three hashes are in our free blocklists tonight.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=sandworm-s-cyclops-blink-is-back-on-your-cisco-firewall-manager-our-harvester-had-the-poc-32-days




Comments