Cisco FMC-Schwachstellen ausgenutzt für Credential-Diebstahl und Qilin-Ransomware
Teaser aus der Quelle
Drei Bedrohungscluster haben kürzlich gepatchte Schwachstellen im Secure Firewall Management Center (FMC) von Cisco ausgenutzt. Die Angriffe nutzen die Authentifizierungsumgehungsschwachstelle CVE-2026-20079, um unberechtigten Zugriff zu erlangen und Qilin-Ransomware einzusetzen. Unternehmen sollten sicherstellen, dass ihre Systeme auf dem neuesten Stand sind.
Dies ist ein Anriss aus dem RSS-Feed. Den vollständigen Artikel liest du beim Original.
Artikel bei The Hacker News lesen →Verknüpfte Empfehlungen
- CVE-2026-20079Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management — Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulner…
- CVE-2026-20079cvelistv5:CVE-2026-20079
- CVE-2026-20079Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
- CVE-2026-20079Cisco Secure Firewall Management Center: Mehrere Schwachstellen
Mehr zu Credentials
Weitere Empfehlungen
- CVE-2026-86993mediumn8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
- CVE-2026-17038noneDrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the…
- osv:CVE-2026-61614noneSolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history
- osv:CVE-2026-85216noneMISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
- CVE-2026-15933noneOptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service pa…
- osv:CVE-2026-55221noneBoruta: OAuth credentials exposed in Boruta business logs
- CVE-2026-55854noneMariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadb
- CVE-2026-55854noneMariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadb
Weitere News-Einträge
- Newsdarkreading2026-09-08Attackers Use Multi-Hop Google Redirects for Phishing Campaign
- Newsthehackernews2026-09-08Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
- Newstheregister-security2026-09-08BigBear phishing crew nets thousands of Microsoft 365 credentials
- Newsthehackernews2026-09-08FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
- Newscsoonline2026-09-08Security leaders must prepare for likely threats, not sensationalized agentic attacks
- Newscsoonline2026-09-08Securing AI agents: Key controls and best practices
- Newsbleepingcomputer2026-09-07BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
- Newsthehackernews2026-09-05Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
Quelle: https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html
ID