Cisco confirmed on September 9 that attackers are exploiting a CVSS 10.0 bypass in its Firewall Management Center to run code as root. CISA added it to its Known Exploited Vulnerabilities list the same day, with a three-day deadline for federal agencies.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence64
Cisco Talos links China-nexus UAT-11587 to 16 affected or targeted institutions in eight Asian countries, via a backdoor run through Microsoft 365. Its commands move through Outlook and OneDrive via Microsoft Graph, so defenders have no command server to block.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 63%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption30
- Hype gap+8
- Incentives
- Insufficient
- Confidence65
Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
Cisco Talos found a 16.4MB Go implant that asks DeepSeek, Qwen, Mistral and Gemini what to do next and acts on the winning vote, treating the providers themselves as its C2 infrastructure. Talos has no confirmation it was ever deployed.
Perspective Coverage
7 publishers
- Builder
- Builder 28%
- Operator
- Operator 66%
- Investor
- Investor 6%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+30
- Incentives45
- Confidence62
Ontinue says the Python implant takes tasking from SharePoint dead drops over Graph API, relays interactive sessions through Teams TURN, and moves all of it through the victim's own headless Edge.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence60
Cisco Talos says a Chinese-speaking crew paired PentestGPT and DeepAudit with Metasploit and a 170,000-URL target list to compromise web servers at scale. Every entry flaw named is years old.
Reality
- Evidence62
- Adoption20
- Hype gap+30
- Incentives65
- Confidence62
Talos says a $300 offer for an hour's phone consultation is the first stage of a con that screens security practitioners for useful access. Targets who pass end up paid to pull non-public material from co-workers and internal systems.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
CVE-2026-20079 hands unauthenticated attackers root on Secure Firewall Management Center. CISA wants federal boxes fixed by September 12. The hot fix closes the path but does not evict anyone who already walked it.
Perspective Coverage
6 publishers
- Builder
- Builder 23%
- Operator
- Operator 65%
- Investor
- Investor 12%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence74
Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−5
- Incentives55
- Confidence60
OpenSourceMalware says WeaselBiscuit borrows functions from DPRK's BeaverTail and OtterCookie but strips out the persistence and the wallet drainer. It runs from memory on an npm import and takes Chrome's extension storage.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Gambit says a single actor pointed the Strix, Cairn and Hermes agent frameworks at online retailers from July onward, taking more than 600,000 valid card records from two victims and leaving skimmers on 119 sites.
Reality
- Evidence58
- Adoption62
- Hype gap+14
- Incentives62
- Confidence60
Eclypsium tracked 158 infrastructure advisories between August 25 and September 17. The exploited maximum-severity flaws it highlights are authentication bypasses in Cisco's Firewall Management Center and Identity Services Engine.
Reality
- Evidence62
- Adoption72
- Hype gap+14
- Incentives65
- Confidence58
Cisco Talos read CLOSEDQUORUM statically: a Go binary that polls DeepSeek, Qwen, Mistral and Gemini before it touches LSASS. The distributed sample has dummy keys. One answering provider can carry the vote.
Reality
- Evidence58
- Adoption8
- Hype gap+25
- Incentives60
- Confidence55
Cisco Talos says its CLOSEDQUORUM sample asks four language models for executable decisions, tallies the votes and acts on the winner. An entire phase of the attack runs while the operator is offline.
Reality
- Evidence50
- Adoption8
- Hype gap+40
- Incentives62
- Confidence54
Cisco Talos has published CLOSEDQUORUM, a Windows credential stealer with no command-and-control server. It hands the state of the infected host to Gemini, DeepSeek, Qwen and Mistral, then acts on the majority verdict.
Reality
- Evidence52
- Adoption15
- Hype gap+18
- Incentives68
- Confidence55
Cisco Talos released its CAIRN framework on September 22nd to hunt prompts, provider endpoints and API-key prefixes in malware metadata. Its first case study polls four commercial models and runs the winner.
Reality
- Evidence58
- Adoption18
- Hype gap+10
- Incentives60
- Confidence55
Cisco Talos has open-sourced CAIRN, a framework that tags malware by the traces its AI calls leave in metadata. The first sample it surfaced polls DeepSeek, Qwen, Mistral and Gemini for orders and decides for itself.
Reality
- Evidence55
- Adoption18
- Hype gap+26
- Incentives62
- Confidence58
Cisco Talos says three separate clusters, one sharing tooling with Sandworm, worked the same CVSS 10.0 bypass in Secure Firewall Management Center. The scope change in that vector reaches every firewall the console manages.
Reality
- Evidence72
- Adoption61
- Hype gap+8
- Incentives38
- Confidence68
A single September 2026 KEV batch produced 1,262,273 GitLab matches and nothing at all for Cisco Secure Firewall Management Center, because the console holding one of the two 10.0 bugs is the one passive scanning cannot fingerprint.
Reality
- Evidence45
- Adoption55
- Hype gap+10
- Incentives70
- Confidence50
Cisco patched CVE-2026-20079 in March 2026 and confirmed in September that attackers had used it in August. Talos ties three clusters to the console, including one it links to Sandworm tooling and a Qilin affiliate.
Reality
- Evidence74
- Adoption72
- Hype gap+5
- Incentives38
- Confidence62
Earlier coverage
- Talos argues defenders are already behind the models they have
Security · September 17, 2026 · 1 publisher
- Talos puts 78% of Japan's ransomware victims under JPY 1 billion in capital
Security · September 17, 2026 · 1 publisher
- Talos wants exploit filtering upstream of OT that certification has frozen
Security · September 16, 2026 · 1 publisher
- A process created at boot lets one HTTP request take root on Cisco's firewall console
Build · September 14, 2026 · 1 publisher
- Talos splits security burnout into four injuries with four different fixes
Security · September 10, 2026 · 1 publisher
- Talos ties a fake Google CAPTCHA to a DLL executing from a remote WebDAV share
Security · September 8, 2026 · 1 publisher
- Talos found ClickFix operators moving their skimmer into a Tampermonkey userscript
Product · September 8, 2026 · 1 publisher
- ClickFix crews shift paste target to Chrome address bar or Tampermonkey
Security · September 8, 2026 · 1 publisher
- Higher reasoning settings produced blocked responses in Talos's 66-combination model test
Security · August 27, 2026 · 1 publisher
- Seven RAT families, one actor: what SilkParasite does to behavioural clustering
Security · August 27, 2026 · 2 publishers
- Talos: obfuscated JavaScript is phishing kit plumbing, and beautifiers will not read it for you
Security · August 27, 2026 · 1 publisher
- Talos ran 66 model settings at one log-review task and refused to name a winner
Security · August 26, 2026 · 1 publisher
- Count the refusals: Talos turns model guardrails into a procurement number
Security · August 25, 2026 · 1 publisher
- Talos puts a name to the AI retry loop: UAT-10147 fixes its own failed exploits
Build · August 20, 2026 · 1 publisher
- Talos finds a commodity crew running agentic AI, and a target list of 170,000 URLs
Security · August 20, 2026 · 1 publisher
- An SEO fraud crew is now shipping kernel rootkits and BYOVD, and that is the story
Security · August 20, 2026 · 1 publisher
- Talos tells the story instead of the matrix, and BEC's new economics fall out
Security · August 20, 2026 · 1 publisher