SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefThursday, September 10, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Cisco Secure FMC Auth Bypass Actively Exploited | CRITICAL |
|
5 C2 IPs | 82 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by the active exploitation of CVE-2026-20079, a maximum-severity authentication bypass in Cisco Secure FMC, alongside a Chrome V8 zero-day (CVE-2026-87491) leveraged by multiple Chinese cyber-espionage groups using the "BlueMoon" exploit kit. Additionally, threat actors are increasingly targeting AI infrastructure through distillation attacks on frontier models and bypassing MFA via replayable AI tokens harvested from infostealer logs. |
|
■ CRITICAL STORIES Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks This maximum-severity authentication bypass vulnerability allows unauthenticated attackers to gain complete control over Cisco Secure Firewall Management Center (FMC) software, and its active exploitation poses an immediate risk to enterprise perimeter security. |
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox The active exploitation of CVE-2026-87491 by multiple Chinese state-sponsored espionage groups using the "BlueMoon" exploit kit highlights a coordinated effort to compromise endpoints via browser-based zero-days. |
US says Chinese firms extracted billions of tokens from frontier AI models Six Chinese AI companies have been conducting industrial-scale distillation attacks to systematically extract proprietary capabilities from American frontier models like GPT, Claude, and Gemini, representing a significant intellectual property threat. |
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA Cybercriminals are harvesting session tokens from infostealer logs (like Lumma Stealer) to hijack active AI sessions from providers like Google and Anthropic, effectively bypassing multi-factor authentication (MFA) protections. |
|
■ CVEs IDENTIFIED CVE-2026-20079 Cisco Secure Firewall Management Center (FMC) — Authentication bypass leading to full compromise |
CVE-2026-87491 Google Chrome (V8 Engine) — Code execution inside browser sandbox |
[CVE-TBD] Skullcandy Dime 3 wireless earbuds — Bluetooth hijacking without user interaction |
[CVE-TBD] Proxmox VE (v7) — Unauthorized access/control of older virtual environments |
|
■ THREAT ACTORS ShinyHunters | Cybercrime Group |
Attributed to a July cyberattack exposing 4.1 million AdaptHealth patient records |
BlueMoon | Exploit Kit / Threat Cluster |
Chaining Windows and Chrome zero-days for cyber-espionage campaigns |
DoppelCart | Cybercrime Group |
Operating over 100,000 fake retail stores to steal payment card details and MFA codes |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Active exploitation of Cisco Secure FMC (CVE-2026-20079) and Plex Media Servers |
| T1203 | | Exploitation for Client Execution | Chrome V8 zero-day (CVE-2026-87491) exploited by Chinese espionage groups |
| T1566 | | Phishing | Passkey-themed social engineering and YouTube gaming lures/SEO poisoning used to deliver malware |
| T1539 | | Steal Web Session Cookie | Infostealer logs (Lumma) used to harvest replayable AI session tokens to bypass MFA |
| T1078 | | Valid Accounts | Abuse of hijacked AI session tokens and compromised passkey identities |
| T1114 | | Email Collection | Threat actors accessing email data via Microsoft Graph after social engineering compromise |
|
■ PATCH PRIORITY Cisco Secure FMC — Active exploitation of maximum-severity auth bypass CVE-2026-20079 — [BC] |
Google Chrome — Active exploitation of V8 zero-day CVE-2026-87491 — [THN] |
Microsoft Windows & Products — September 2026 Patch Tuesday addressing 964 flaws and 2 zero-days — [MWB] |
Fortinet FortiMonitorOnSight & Chrome Extension — Critical unauthenticated bypass vulnerabilities — [SW] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Cisco Secure Firewall Management Center (FMC) immediately to address the actively exploited authentication bypass vulnerability (CVE-2026-20079). |
| 2 | [P1] Update Google Chrome to the latest version to mitigate the actively exploited V8 engine zero-day vulnerability (CVE-2026-87491). |
| 3 | [P1] Apply Microsoft's September 2026 Patch Tuesday updates to resolve 964 vulnerabilities, including two actively exploited zero-days. |
| 4 | [P2] Implement strict session lifetime limits and monitor for anomalous API requests to prevent the abuse of stolen AI session tokens harvested from infostealer logs. |
| 5 | [P2] Update Fortinet FortiMonitorOnSight and the associated Chrome extension to remediate critical authentication bypass vulnerabilities. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |