CuraSec

tag: State-Sponsored · 1 items

2026-09-11 · BleepingComputer · source ↗ #cisco-fmc#ransomware#state-sponsored
  • Engineer — Act: Two patched Cisco FMC vulnerabilities are confirmed exploited in the wild by multiple threat clusters. Patch Cisco Secure Firewall Management Center to the latest fixed version immediately and audit FMC access logs for signs of unauthorized activity.
  • SOC/IR — Act: Active exploitation by ransomware and state-sponsored actors across three clusters means assume-breach posture for any org running Cisco FMC. Hunt for unauthorized FMC access and policy changes since the vulnerability window; pull TTPs from the Cisco Talos advisory and map to ATT&CK for detection coverage.
  • Leader — Act: Exploitation by both ransomware and state-sponsored actors across three clusters elevates this beyond routine CVE noise. Confirm whether your organization runs Cisco FMC, verify your team has patched, and brief leadership if FMC is part of your network security architecture.