Cisco confirmed on September 9 that attackers are exploiting a CVSS 10.0 bypass in its Firewall Management Center to run code as root. CISA added it to its Known Exploited Vulnerabilities list the same day, with a three-day deadline for federal agencies.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence64
Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
NCC Group counted 1,073 ransomware attacks in August, a second straight 2026 high and 12% above July. Industrial companies took 31% of them, up from 28% in July, so the hardest-hit sector drew a larger slice of a larger total.
Publishers:infosecurity-magazine.com · nccgroup.com Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence55
Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.
Perspective Coverage
3 publishers
- Builder
- Builder 12%
- Operator
- Operator 76%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence60
Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.
Perspective Coverage
17 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence62
CVE-2026-20079 hands unauthenticated attackers root on Secure Firewall Management Center. CISA wants federal boxes fixed by September 12. The hot fix closes the path but does not evict anyone who already walked it.
Perspective Coverage
6 publishers
- Builder
- Builder 23%
- Operator
- Operator 65%
- Investor
- Investor 12%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence74
Microsoft says affiliate Storm-2570 has run the same remote access and exfiltration tools whether it deploys Qilin, DragonForce, Anubis or BERT ransomware. Detections built on those tools can catch the operator before any payload runs.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence55
Cisco Talos's weekly newsletter says the newest models add only incremental cybersecurity capability, and that defensive use has not kept up with the ones already shipped.
Reality
- Evidence36
- Adoption42
- Hype gap+8
- Incentives62
- Confidence44
Intel 471's 18-month sweep of the underground counted 340 financial-sector extortion victims across 74 countries, 159 firms with access for sale and 562 claimed DDoS attacks. The dated intrusions came in through vendors and help-desk calls.
Reality
- Evidence40
- Adoption55
- Hype gap+22
- Incentives78
- Confidence47
Comparitech's half-year tally shows government ransomware growing again, with the newest crew on the board, The Gentlemen, out-filing Qilin and spreading its targeting well beyond the United States.
Publishers:comparitech.com
Reality
- Evidence50
- Adoption60
- Hype gap+20
- Incentives62
- Confidence55
Bitdefender puts 84% of its high-severity incidents on binaries that were already installed on the host. That figure and Microsoft's ClickFix number cover the two largest volume plays in the telemetry, and both sit outside what attachment scanning and patch cycles reach.
Reality
- Evidence55
- Adoption72
- Hype gap+15
- Incentives72
- Confidence58
Bitdefender logged 873 claimed ransomware victims in July, the third-highest month in a year. A brand that barely existed in June supplied 46 of them, on a leak site the analysts say they cannot fully verify.
Publishers:bitdefender.com
Reality
- Evidence38
- Adoption26
- Hype gap+42
- Incentives64
- Confidence44
The National Cybersecurity Plan 2025-2030 loads its operational machinery into a single legislative year. Firms operating in Mexico should budget for weak state incident response until it lands.
Reality
- Evidence54
- Adoption31
- Hype gap+28
- Incentives68
- Confidence46