Skip to content

other

Sandworm

Russian military intelligence (GRU) hacking unit known for destructive attacks like NotPetya and strikes on Ukraine's power grid.

Known aliases

  • APT44
  • IRON VIKING
  • Military Unit 74455
  • Russian APT Sandworm
  • Russian state-backed APT group
  • Sandworm Team
  • Seashell Blizzard

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3

Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence55
security3 publishers

Leaked Bauman files name the GRU department that fed graduates into APT28 and Sandworm

A media consortium and DomainTools worked through more than 2,000 records from a Moscow engineering department that appears on no public org chart, and found roughly 250 students on a documented path into Russian military intelligence.

Perspective Coverage

3 publishers
Builder
Builder 25%
Operator
Operator 65%
Investor
Investor 10%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence60
security6 publishers

Cisco's own July 23 log indicator predates its August date for FMC exploitation

CVE-2026-20079 hands unauthenticated attackers root on Secure Firewall Management Center. CISA wants federal boxes fixed by September 12. The hot fix closes the path but does not evict anyone who already walked it.

Perspective Coverage

6 publishers
Builder
Builder 23%
Operator
Operator 65%
Investor
Investor 12%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives60
Confidence74