Daily Security Intel

Archives
Log in
Subscribe
September 10, 2026

[SecurityIntel] 10 Sep | Cisco Secure FMC Auth Bypass Actively Exploited

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, September 10, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Cisco Secure FMC Auth Bypass Actively Exploited

CRITICAL

5

C2 IPs

82

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by the active exploitation of CVE-2026-20079, a maximum-severity authentication bypass in Cisco Secure FMC, alongside a Chrome V8 zero-day (CVE-2026-87491) leveraged by multiple Chinese cyber-espionage groups using the "BlueMoon" exploit kit. Additionally, threat actors are increasingly targeting AI infrastructure through distillation attacks on frontier models and bypassing MFA via replayable AI tokens harvested from infostealer logs.

■ CRITICAL STORIES

CRITICAL#1

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

This maximum-severity authentication bypass vulnerability allows unauthenticated attackers to gain complete control over Cisco Secure Firewall Management Center (FMC) software, and its active exploitation poses an immediate risk to enterprise perimeter security.

CRITICAL#2

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

The active exploitation of CVE-2026-87491 by multiple Chinese state-sponsored espionage groups using the "BlueMoon" exploit kit highlights a coordinated effort to compromise endpoints via browser-based zero-days.

HIGH#3

US says Chinese firms extracted billions of tokens from frontier AI models

Six Chinese AI companies have been conducting industrial-scale distillation attacks to systematically extract proprietary capabilities from American frontier models like GPT, Claude, and Gemini, representing a significant intellectual property threat.

HIGH#4

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are harvesting session tokens from infostealer logs (like Lumma Stealer) to hijack active AI sessions from providers like Google and Anthropic, effectively bypassing multi-factor authentication (MFA) protections.

■ CVEs IDENTIFIED

CVE-2026-20079

Cisco Secure Firewall Management Center (FMC) — Authentication bypass leading to full compromise

Critical

CVE-2026-87491

Google Chrome (V8 Engine) — Code execution inside browser sandbox

Medium

[CVE-TBD]

Skullcandy Dime 3 wireless earbuds — Bluetooth hijacking without user interaction

Medium

[CVE-TBD]

Proxmox VE (v7) — Unauthorized access/control of older virtual environments

High

■ THREAT ACTORS

ShinyHunters

Cybercrime Group

Attributed to a July cyberattack exposing 4.1 million AdaptHealth patient records

BlueMoon

Exploit Kit / Threat Cluster

Chaining Windows and Chrome zero-days for cyber-espionage campaigns

DoppelCart

Cybercrime Group

Operating over 100,000 fake retail stores to steal payment card details and MFA codes

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Active exploitation of Cisco Secure FMC (CVE-2026-20079) and Plex Media Servers
T1203
Exploitation for Client Execution | Chrome V8 zero-day (CVE-2026-87491) exploited by Chinese espionage groups
T1566
Phishing | Passkey-themed social engineering and YouTube gaming lures/SEO poisoning used to deliver malware
T1539
Steal Web Session Cookie | Infostealer logs (Lumma) used to harvest replayable AI session tokens to bypass MFA
T1078
Valid Accounts | Abuse of hijacked AI session tokens and compromised passkey identities
T1114
Email Collection | Threat actors accessing email data via Microsoft Graph after social engineering compromise

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Cisco Secure FMC — Active exploitation of maximum-severity auth bypass CVE-2026-20079 — [BC]

[P1 PATCH NOW]≤24h

Google Chrome — Active exploitation of V8 zero-day CVE-2026-87491 — [THN]

[P1 PATCH NOW]≤24h

Microsoft Windows & Products — September 2026 Patch Tuesday addressing 964 flaws and 2 zero-days — [MWB]

[P1 PATCH NOW]≤24h

Fortinet FortiMonitorOnSight & Chrome Extension — Critical unauthenticated bypass vulnerabilities — [SW]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Cisco Secure Firewall Management Center (FMC) immediately to address the actively exploited authentication bypass vulnerability (CVE-2026-20079).
2[P1] Update Google Chrome to the latest version to mitigate the actively exploited V8 engine zero-day vulnerability (CVE-2026-87491).
3[P1] Apply Microsoft's September 2026 Patch Tuesday updates to resolve 964 vulnerabilities, including two actively exploited zero-days.
4[P2] Implement strict session lifetime limits and monitor for anomalous API requests to prevent the abuse of stolen AI session tokens harvested from infostealer logs.
5[P2] Update Fortinet FortiMonitorOnSight and the associated Chrome extension to remediate critical authentication bypass vulnerabilities.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 11 Sep | AI-driven agents and zero-days fuel global exploitation. Older → [SecurityIntel] 09 Sep | Microsoft Patches Record 974 Flaws, Two Zero-Days
Powered by Buttondown, the easiest way to start and grow your newsletter.