Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
12 hours ago

Tenable Security Intel Brief: Cisco firewall consoles under attack

Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team.

This week, Cisco Talos tied a state-linked APT, a ransomware operator, and a credential thief to exploitation of Cisco's firewall management console. The brief also covers federal cyber teams boarding two energy tankers in the Gulf of Mexico, a follow-up on the Gitea flaw from our September 2 edition with 11 confirmed victims, and three nations jointly exposing an Iranian spyware campaign running on Telegram bots.

Ransomware and state-linked hackers break into Cisco firewall consoles →

Brief: Cisco Talos tied three threat clusters, including an advanced persistent threat (APT) actor and a ransomware operator, to exploitation of two flaws in Cisco Secure Firewall Management Center (FMC), the console that centrally manages Cisco firewalls.

Intel: CVE-2026-20079, a CVSSv3 10.0 authentication bypass, lets an unauthenticated remote attacker gain root access, and CVE-2026-20316 is a static credential on a low-privileged account. UAT-11823, an APT actor whose tooling overlaps with Sandworm's, harvested configurations of the devices FMC manages and deployed a Cyclops Blink variant. UAT-11988 logged in with that credential and later deployed Qilin ransomware, while UAT-12197 stole stored credentials. Cisco says its hot fixes stop new exploitation but do not clean devices already compromised.

Why it matters: State-linked and criminal intruders both went after these consoles, which hold privileged access to the firewalls they manage. The 2022 version of Cyclops Blink targeted WatchGuard devices; the variant found on these consoles runs on generic Linux, so Sophos says compatible SD-WAN controllers and VPN concentrators are plausible targets too.

Federal cyber teams board energy tankers to hunt intrusions at sea →

Brief: Joint USCG and FBI teams boarded two energy tankers in the Gulf of Mexico in August following what officials called indications that the vessels' networks were "compromised by foreign cyber actors."

Intel: USCG Cyber Protection Team members and FBI Cyber Action Team operators spent four days aboard the tanker VL Prosperity; a second tanker was boarded August 24. Rear Adm. Amy Grable, commander of U.S. Coast Guard Cyber Command, confirmed to CBS News that investigators found malicious activity. Her central concern: the ship's IT systems linked to the systems that control propulsion and navigation. The U.S. has not named a country; Iran's Mehr News Agency reported the attack, citing an unnamed crew member, and former Coast Guard official Quinton DuBose cautioned that the Iranian narrative remains unverified.

Why it matters: Boarding VL Prosperity was one of roughly 40 to 50 Coast Guard Cyber Protection Team missions in the past year. For nearly 20 ships, cyber threats now affect port entry: citing U.S. officials, Bloomberg reports agencies are tracking them, and the Coast Guard has asked for advance notice before any enters a U.S. port.

Red Heron breached 11 organizations through a Gitea flaw →

Brief: Acronis Threat Research Unit (TRU) linked 11 confirmed breaches to Red Heron, a Chinese-speaking operator assessed with moderate confidence to be PRC-linked, who began turning public exploit code for CVE-2026-60004 into attack tools two days after its patch shipped.

Intel: We covered CVE-2026-60004 in our September 2 edition after CISA added it to the Known Exploited Vulnerabilities catalog; Acronis has since traced confirmed victims to Red Heron, who by July 30 had scanned 1,386 internet-facing Gitea instances, identified 128 that let anyone sign up, and selected targets in sectors including defense, elections, energy, and government. Red Heron's staging server also held the JITTERLY implant, which carries SIXZUT, a previously undocumented rootkit that hides the intruder's files and brings the implant back if it is shut down.

Why it matters: Red Heron had scanned 1,386 Gitea instances across seven countries within three days of the fix shipping. A month after that fix, 8,393 servers remained vulnerable per Shadowserver. Patch schedules built for a scanning window of weeks are now racing one measured in days.

Three nations expose Iranian spyware run through Telegram bots →

Brief: A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI, and the Netherlands' General Intelligence and Security Service (AIVD) exposes CHOSEN BRICK, Iranian state malware targeting dissidents, activists, and journalists in at least three countries.

Intel: Published September 15, 2026, the advisory attributes CHOSEN BRICK, used from at least 2025, to "Iranian state cyber actors." Lures include fake app installers like Pictory and KeePass, and a fake MRI scan. CHOSEN BRICK harvests contacts, emails, and screen captures, exfiltrating through Telegram and cloud storage. Each victim is assigned their own dedicated Telegram bot, isolating compromised devices from one another. The FBI issued a separate alert naming the malware HEAVYGRAM and attributing it to Iran's Ministry of Intelligence and Security (MOIS), an assessment the joint advisory does not make.

Why it matters: The malware's command-and-control runs through Telegram, which the advisory says helps it blend in with legitimate processes. Giving each victim a dedicated bot means uncovering one infection does not expose the others.

Stat of the week: 1 million+

The number of emails detected in a single financial fraud campaign between August 3 and 5, with templates showing indicators consistent with generative AI use, according to Microsoft.

Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.

No RepliesBe the first to reply