PUBLISHED ON
Four Crews Shared BlueMoon While Cisco FMC Went Root
Record patches, a shared zero day kit, and root on the firewall manager
WEEKLY OPENING
Good evening. The week did not wait for your change window. Microsoft shipped a record Patch Tuesday north of 960 fixes, two of them already on the Known Exploited Vulnerabilities catalog, while Cisco Secure Firewall Management Center took unauthenticated root and then hosted three different businesses on the same console. A shared exploit kit put two Chrome flaws and a Windows ALPC privilege escalation into four espionage shops inside roughly twelve days. Artifactory handed out admin tokens to strangers. Passkey themed helpdesk calls turned into Graph collection. ClickFix moved into the browser and borrowed Google Sheets as the drop box. If your mental model still starts at the laptop, the logs started at the manager.
EXECUTIVE TAKE
Operational risk sat on control planes that already hold credentials, policy, and software supply: Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, self hosted JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Consulted sources confirm in the wild use on multiple of those flaws, which is evidence of abuse rather than a marketing score. Cisco Talos then showed what login looks like after the prompt: webshells and credential dumps, a Cyclops Blink implant with tooling overlap to Sandworm, and a Qilin consistent affiliate building an encryption target list from the firewall manager itself.
Identity was the second control plane. Microsoft described passkey and SSO lures that do not need a completed passkey enrollment to win. Adversary in the middle and device code flows, then attacker registered MFA, then Graph enumeration and measured SharePoint, OneDrive, and mailbox collection. Named operators in that ecosystem include Storm-3121 and Storm-3032. Treat the helpdesk call and the cloud audit log as one incident or you will close the ticket after the first factor and miss the second.
Patch volume is now a capacity problem. Consulted sources put September's Microsoft release at 964 to 974 CVEs with about 113 critical ratings and two exploited Windows privilege escalation bugs, CVE-2026-81963 and CVE-2026-85880. That is not an instruction to patch everything by Friday. It is an instruction to patch what is already being used, then the unauthenticated network RCEs Microsoft itself flags as more likely, and to assume internet facing management interfaces were probed before the hotfix landed.
Two further patterns change procurement and incident posture, not just the queue. Advisory AA26-251A jointly named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI for industrial scale distillation of United States frontier models. Wiz documented chaining of CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 on Artifactory through 2026-09-08, yielding admin takeover, Groovy plugins, and Rust backdoors. StyleSmuggler on Adobe Commerce, CVE-2026-75650, was exploited before the hotfix. Several items this week require incident response posture because the fix does not evict a pre existing implant.
KEY FINDINGS
[+] Microsoft September Patch Tuesday addressed 964 to 974 vulnerabilities with about 113 rated critical. CVE-2026-81963 and CVE-2026-85880 are confirmed exploited and listed on CISA KEV.
[+] CVE-2026-81963 is a Windows Update Stack link following elevation of privilege, CVSS 7.8, the first Update Stack flaw attackers reached before Microsoft since the 2022 series began.
[+] CVE-2026-85880 is a Windows ALPC heap overflow elevation of privilege from AppContainer to SYSTEM, CVSS 7.8, exploited in the wild and used as the kernel stage of the BlueMoon chain.
[+] CVE-2026-69730 is a Windows DNS unauthenticated RCE, CVSS 9.8, flagged by Microsoft as more likely. CVE-2026-69829 is a Windows Shell unauthenticated RCE, CVSS 9.8. CVE-2026-62916 is an Entra ID network elevation of privilege. None of those three had confirmed exploitation in consulted sources this week.
[+] Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass to root via crafted web interface requests, CVSS 10.0, actively exploited, CISA KEV, federal clock cited as 2026-09-12.
[+] Cisco FMC CVE-2026-20316 is a static or low privilege login that Talos observed chained for root via package_info.pl and license.tmp.
[+] UAT-12197 exploited CVE-2026-20079 and deployed home.jsp plus cmd.jar to query user tables on FMC.
[+] UAT-11823 is attributed by Cisco Talos with high confidence to an APT whose tooling overlaps Cyclops Blink, previously associated with Sandworm by the United States and the United Kingdom. Treat Sandworm as under attribution for this intrusion, not a fresh joint finding.
[+] UAT-11988 is attributed by Cisco Talos with high confidence to a ransomware operator whose follow on activity was consistent with Qilin: static credentials, package_info.pl living off the land, LDAP SMB WinRM tunnels, AV killers, then encryption.
[+] BlueMoon is a Proofpoint tracked shared exploit kit chaining CVE-2026-85046 and CVE-2026-87491 in Chrome V8 with CVE-2026-85880. At least four espionage motivated clusters adopted it within roughly twelve days of first observed use.
[+] APT31, also tracked as JungleBamboo, TA412, and Violet Typhoon, was the first observed BlueMoon operator on 2026-08-28, with targets including NGOs, mining, aerospace, and manufacturing in Southeast Asia. Remaining operators carry a suspected China nexus. Payload names GemStone and ShadowPad appeared in single source reporting and stay unconfirmed here.
[+] CISA KEV additions in the window included CVE-2026-20079, CVE-2026-19490 Citrix NetScaler auth bypass, CVE-2025-25249 Fortinet heap overflow, CVE-2026-87491 Chromium V8, CVE-2026-42016 and CVE-2026-42018 Artifactory, CVE-2026-84869 ScreenConnect, CVE-2026-67277 and CVE-2026-86060 MikroTik RouterOS, CVE-2026-75650 Adobe Commerce, CVE-2026-86218 N-able N-central, plus the two Windows exploited zero days.
[+] CVE-2026-19490 on Citrix NetScaler ADC and Gateway is an authentication bypass, CVSS about 9.3 vendor and 9.8 NVD. Public proof of concept landed around 2026-09-02. Probing followed within a day. Honeypot telemetry in consulted sources ranged from 10 attempts across 6 IPs to 56 attempts with 36 in a single day. Successful compromise was not established.
[+] CVE-2025-25249 on Fortinet FortiOS, FortiSwitchManager, and FortiSASE is a heap overflow added to KEV with a 2026-09-12 deadline. Secondary reporting ties it to a Node.js RAT called PivotC2 against roughly 178 devices out of about 3000 targeted IPs. Actor remains under attribution.
[+] Wiz documented in the wild chaining of JFrog Artifactory CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329 from 2026-08-15 through 2026-09-08: anonymous JWT or unauthenticated registry join, admin token, persistent admins, malicious Groovy plugins, Rust backdoors under /dev/shm and /tmp/.z.
[+] CVE-2026-75650 StyleSmuggler is a CVSS 10.0 unauthenticated RCE in Adobe Commerce and Magento via template engine injection. Exploitation observed from 2026-09-04, hotfix 2026-09-07. Implant masquerades as fc-cache and chronyd with a 5 minute cron restart. Later variants added arm64 support.
[+] CVE-2026-84869 on ConnectWise ScreenConnect allows file transfer and execute through an active session without host confirmation, CVSS 9.9. Consulted sources describe three unrelated incidents dropping VBScript. Fixed line cited as 26.6.5.
[+] MikroTik RouterOS CVE-2026-67277 and CVE-2026-86060, sometimes described as MikroTrick, enable unauthenticated takeover. CISA KEV due date cited as 2026-09-13 for federal civilian executive branch.
[+] Microsoft observed passkey themed social engineering since 2026-05 leading to unusual sign in, attacker enrolled auth methods including SoftwareTokenActivated and NO_DEVICE patterns, Graph reconnaissance, then SharePoint OneDrive Exchange collection via REST. Storm-3121 and Storm-3032 are named among operators.
[+] Cisco Talos tracked a ClickFix campaign that never needs a disk resident stealer: victims paste JavaScript or install Tampermonkey, payload arrives from a public Google Sheet through the Visualization API, C2 rides legitimate Google infrastructure, crypto deposit addresses and clipboard get swapped.
[+] Google GTIG reporting published in the window describes adversaries moving from prompt abuse to autonomous agent driven credential harvesting in compromised cloud environments, with execution under 30 minutes from breach to campaign in observed cases. UNC6780 TeamPCP remains the named open source supply chain case. Treat this as quarterly tradecraft published this week, not a newly confirmed campaign start.
[+] NSA, CISA, and FBI advisory AA26-251A named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI for industrial scale distillation of United States frontier models via fraudulent accounts and proxy transfer stations since late 2024.
[+] Chinese aligned clusters chained CVE-2026-85046 and CVE-2026-87491 with CVE-2026-85880 for espionage from late August, overlapping the BlueMoon kit story and the Patch Tuesday ALPC fix.
[+] PaperCut CVE-2026-82078 and CVE-2026-81578 were added to CISA KEV in consulted sources, with exploitation against education targets and Metasploit post exploitation noted.
[+] SonicWall SMA 1000 CVE-2026-83548, CVSS 10.0, and CVE-2026-83549 were confirmed exploited, with BSI, Singapore CSA, and CISA advisories cited.
[+] GitLab emergency patches for a critical path traversal appeared in some consulted sources with internet wide scans. Other consulted sources did not corroborate a KEV listing inside the window. Treat exposure hunts as prudent and the catalog status as unverified here.
[+] CISA ICS advisories in the window covered AVEVA Pipeline Integrity Monitor ICSA-26-253-01, NextGen Mirth Connect ICSMA-26-253-01, Orthanc DICOM, and ST Engineering iDirect.
[+] SANS ISC reported a Proxmox management interface scanning surge, Redtail payload analysis, and AI agent harvesting that resells stolen LLM access, including a seven agent GitSpawn style campaign.
[+] Anthropic threat reporting spanning late 2025 through 2026-08 described Russian aligned espionage against 20 plus organizations, a Chinese undergraduate exploit foundry, AI enabled bio and chem misuse, and distillation campaigns. That is published context, not a single new intrusion this week.
[+] Microsoft released a Cloud Web Applications Threat Matrix aligned to ATT&CK for cloud hosted web apps and serverless platforms.
[+] Data exposure and claims in the window: IDScan Nexus about 153 million driver licenses; AdaptHealth 4.1 million individuals from a 2026-06 intrusion; CareCloud about 3.76 million patient records from unauthorized AWS access 2026-03-10 to 2026-03-16; Veradigm vendor credential API breach in an SEC filing, with Gentlemen claiming 3.5 million records unconfirmed; Bavarian municipal utility IT encrypted and OT reported safe; Berlin government second credential leak; Conti developer sentenced to 4 years.
[+] ShinyHunters claimed McKesson at 284 million records and separately claimed Florida driver database access. Interlock claimed NFM Lending at 2.5TB. Those remain unconfirmed by the named organizations.
WEEKLY THREAT NARRATIVE
The firewall manager was the beachhead
Cisco Talos closed an argument that started in July. CVE-2026-20079 is not a theoretical auth bypass on Secure FMC, and CVE-2026-20316 is not a low severity static credential footnote. Unauthenticated script execution to root, or a low privilege login that then runs attacker built license.tmp through legitimate package_info.pl, produced three different outcomes on the same product.
[+] UAT-12197 dropped home.jsp and cmd.jar and queried user tables.
[+] UAT-11823 stood up Netcat, stole managed device configs, and installed a Cyclops Blink variant with DNS over HTTPS, sniffing, and persistence under /etc/init.d/. Tooling overlap with Sandworm is vendor assessed. It is not a new national level statement this week.
[+] UAT-11988 built an internal map, forwarded LDAP Kerberos SMB and WinRM, killed AV, and deployed ransomware consistent with Qilin.
Compromise of a management plane is force multiplication. Credentials and configs harvested there inherit the trust of every device below it. If your network security platform can enumerate Active Directory and push tunnels, it is an identity store that happens to speak firewall.
Citrix CVE-2026-19490 belongs to the same family: an authentication bypass on the appliance fronting the VPN, public proof of concept, live probing inside a day, and a short patch to exploitation window. Fortinet CVE-2025-25249 adds a heap overflow on FortiOS class products with secondary reporting of PivotC2. Management planes are having a worse year than the devices they manage.
Zero days went retail
BlueMoon reframes the patch story. Proofpoint documented at least four espionage motivated actors using a shared modular kit that chains CVE-2026-85046 V8 type confusion, CVE-2026-87491 V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode, and CVE-2026-85880 Windows ALPC kernel elevation, delivered by spearphish links against fully patched Chrome users.
[+] First observed use 2026-08-28 by APT31.
[+] Remaining clusters kept their own malware and C2. Only the kit was shared.
[+] Targets reported include NGOs, mining, aerospace, and manufacturing in the United States and Southeast Asia.
The behavior echoes criminal exploit kit economics from a decade ago, relocated to the nation state tier: one capable supplier, many customers. Your patch latency is now measurable against someone else's rental agreement.
The patch flood is a triage crisis
Microsoft's 964 to 974 fix Tuesday is a warning, not a trophy. With about 113 critical ratings and two KEV listed exploits, the volume overwhelms a standard monthly cycle. Talos released more than 100 Snort rules. Most shops will apply none of them this week. CVE-2026-85880 was already inside BlueMoon before or at release. If you are not prioritizing by KEV plus internet exposure plus exploit maturity, you are guessing.
Tokens, plugins, and the software warehouse
Wiz described a two step that should be burned into every Artifactory hunt.
[+] POST /access/api/v1/aws/token/ returns an internal anonymous JWT under CVE-2026-42018.
[+] POST /access/api/v1/tokens inflates it to admin scope under CVE-2026-42016.
[+] CVE-2026-82329 skips the dance and hands back an admin token from POST /access/api/v1/registry/join.
[+] Persistence used admin names resembling jfrog-distribution or Nxploited_*, Groovy plugin execute, and payloads in /dev/shm and /tmp/.z.
[+] A behavioral tell in some consulted sources is 401 on a bare path followed by 200 on a variant from the same client.
Fixed versions cited span 7.111.21 through 7.161.20 and the sibling branches 7.117.28, 7.125.20, 7.133.29, and 7.146.38. Internet exposed Artifactory should be treated as compromised until logs prove otherwise. CISA later added the 42016 and 42018 pair to KEV.
E commerce got the same treatment
StyleSmuggler, CVE-2026-75650, injects PHP through styles properties in Magento's template engine and executes on rendering of the Payment Transaction Failed Reminder email. No authentication sits in the chain. Exploitation from 2026-09-04 beat Adobe's 2026-09-07 hotfix. The implant pretends to be a kernel thread named fc-cache or chronyd and restarts itself every five minutes. The hotfix stops the next intrusion. It does not remove the current one. Rotate the encryption key and everything it protects.
Passkeys as pretext, Graph as collection
Microsoft's write up is identity tradecraft, not a browser exploit story. The lure is a helpdesk voice or SMS about passkey, MFA, or SSO. The mechanism is adversary in the middle or device code. Persistence is a new phone, authenticator, or software token. Collection is Graph walking /users, /sites, /messages, then file access that stays under a thousand objects an hour so it looks like a busy employee.
[+] Storm-3121 is tied by Microsoft to ShinyHunters and Falcon extortion initial access.
[+] Storm-3032 is described as a BlackFile splinter now under Helix.
That is Microsoft cluster naming, not a claim that every passkey lure this week was those two. GTIG's same week AI tracker is a different layer and should not be flattened into the FMC or Artifactory intrusions.
ClickFix learns browser manners
Talos tracked a cryptocurrency stealer that does not touch the OS. Victims are talked into pasting JavaScript into devtools or configuring Tampermonkey. The payload pulls obfuscated code from a public Google Sheet via the Visualization API. The script hooks fetch and clipboard, swaps deposit addresses, and rides docs[.]google[.]com. Mitigation is role based restriction of devtools and extensions, plus watching Visualization API fetches from non Docs contexts.
AI distillation goes diplomatic
AA26-251A is unusual: three United States agencies named six Chinese commercial AI firms for industrial scale distillation of frontier models from Anthropic, OpenAI, Google, and xAI via fraudulent accounts and proxy transfer stations. Assessed intent is core IP extraction, not incidental scraping. Remediation guidance targets model providers with canary prompts, silent model downgrade, and cross provider intel sharing. Enterprises inherit a procurement problem: how do you verify the vendor is not distilling the competitor.
Trust in remote access, spent cheaply
CVE-2026-84869 on ScreenConnect lets an active session transfer and execute files without host confirmation. Remote access tooling is trusted by design and monitored by accident. MikroTik CVE-2026-67277 and CVE-2026-86060 add unauthenticated RouterOS takeover, with btest exposure as a practical hunt. PaperCut KEV entries and SonicWall SMA 1000 exploitation extend the same lesson to print and remote access concentrators. Every layer that exists to be trusted was tested this week. Several failed in public.
Healthcare's disclosure backlog is surfacing
AdaptHealth, CareCloud, Veradigm, and adjacent health tech notices landed inside the window. Underlying intrusions largely predate the week and reflect filing cadence more than a new connected campaign. ShinyHunters McKesson and Florida driver database claims, plus Interlock on NFM Lending, stay in the claims column until the named organizations confirm.
NOTABLE TECHNICAL SIGNALS
Top CVEs
[+] CVE-2026-20079 Cisco Secure FMC auth bypass to root, CVSS 10.0, Talos in the wild, CISA KEV, due 2026-09-12.
[+] CVE-2026-20316 FMC static or low privilege login chained through package_info.pl and license.tmp, Talos in the wild.
[+] CVE-2026-19490 Citrix NetScaler AAA and Gateway auth bypass, CISA KEV, due 2026-09-12, probes confirmed, successful compromise not established.
[+] CVE-2025-25249 Fortinet FortiOS FortiSwitchManager FortiSASE heap overflow, CISA KEV, due 2026-09-12. PivotC2 linkage remains under attribution.
[+] CVE-2026-87491 Chromium V8 out of bounds write and sandbox escape, patched 2026-09-08, CISA KEV due 2026-09-23, BlueMoon stage.
[+] CVE-2026-85046 Chrome V8 type confusion renderer RCE, patched 2026-09-03, KEV 2026-09-04, BlueMoon stage.
[+] CVE-2026-85880 Windows ALPC heap overflow EoP, CVSS 7.8, exploited, BlueMoon kernel stage, KEV due 2026-09-22.
[+] CVE-2026-81963 Windows Update Stack link following EoP, CVSS 7.8, exploited, KEV due 2026-09-22.
[+] CVE-2026-82329 CVE-2026-42018 CVE-2026-42016 JFrog Artifactory unauth admin or anonymous token to admin chain, Wiz exploitation 2026-08-15 to 2026-09-08, later KEV on 42016 and 42018.
[+] CVE-2026-75650 Adobe Commerce Magento StyleSmuggler unauthenticated RCE, CVSS 10.0, exploited from 2026-09-04.
[+] CVE-2026-84869 ScreenConnect client transfer and execute without host confirmation, CVSS 9.9, CISA KEV.
[+] CVE-2026-67277 CVE-2026-86060 MikroTik RouterOS missing auth and command delimiter issues, CISA KEV due 2026-09-13.
[+] CVE-2026-86218 N-able N-central static code injection, CISA KEV.
[+] CVE-2026-69730 Windows DNS unauthenticated RCE, CVSS 9.8, Microsoft more likely, not listed as exploited.
[+] CVE-2026-81578 CVE-2026-82078 PaperCut, CISA KEV in consulted sources.
[+] CVE-2026-83548 CVE-2026-83549 SonicWall SMA 1000, confirmed exploited.
Attack vectors this week
[+] Internet facing management and edge authentication dominated confirmed exploitation: FMC web UI, NetScaler Gateway and AAA, Fortinet HTTP, Artifactory access APIs, ScreenConnect sessions, RouterOS services, SMA 1000, PaperCut.
[+] Identity plane phishing used voice and SMS passkey pretexts, adversary in the middle, and device code grants, then API collection rather than malware on the endpoint.
[+] Browser social engineering shifted ClickFix from OS paste to in session JavaScript and Tampermonkey, with C2 inside Google Sheets Visualization API traffic.
[+] Spearphish links delivered BlueMoon against patched Chrome.
[+] Patch Tuesday added local EoP and a pile of unauthenticated Windows RCEs that are not yet KEV.
[+] Supply chain and AI agent harvesting appear in GTIG quarterly material published this week and in the Artifactory and StyleSmuggler live chains.
Actor and infrastructure patterns
[+] Named evidence backed clusters: UAT-12197 FMC webshell and JAR, under attribution beyond the cluster ID.
[+] UAT-11823 high confidence APT per Talos, Cyclops Blink overlap with Sandworm, Sandworm attribution for the malware family is prior United States and United Kingdom work.
[+] UAT-11988 high confidence Qilin consistent ransomware operator per Talos.
[+] Microsoft: Storm-3121, Storm-3032, plus others on the same identity playbook.
[+] BlueMoon: APT31 first, then at least three additional espionage clusters with suspected China nexus, separate malware and C2, shared kit only.
[+] GTIG names in Q2 AI misuse context include UNC6780 TeamPCP, UNC6240 ShinyHunters, UNC6508, and additional tracked sets. Do not flatten those into this week's FMC or Artifactory intrusions.
[+] Artifactory operators were multiple and unnamed. Account regexes and IPs are vendor published, not a single crew.
[+] ClickFix in browser remains under attribution.
[+] PivotC2 Russian speaking crimeware remains under attribution.
[+] Observed FMC infrastructure from Talos: home.jsp, cmd.jar, /var/tmp/license.tmp, Netcat FIFO reverse shells, SOCKS5, reverse SSH, and IPs 89.34.96[.]56, 208.123.119[.]215, 104.218.165[.]253, 91.214.78[.]118, 43.204.2[.]142. Validate each indicator against asset role before blocking.
MITRE ATT&CK themes
[+] T1190 Exploit Public Facing Application: FMC, NetScaler, Fortinet, Artifactory, MikroTik, SMA, PaperCut.
[+] T1203 Exploitation for Client Execution: BlueMoon V8 renderer RCE via malicious links.
[+] T1068 Exploitation for Privilege Escalation: CVE-2026-85880 and CVE-2026-81963.
[+] T1566.002 Spearphishing Link: BlueMoon delivery.
[+] T1133 External Remote Services: ScreenConnect session abuse.
[+] T1078.004 Valid Accounts Cloud Accounts: passkey adversary in the middle and device code sequence.
[+] T1556.006 Modify Authentication Process MFA: attacker registered phone, authenticator, or software token.
[+] T1087.004 and T1069.003 Cloud Account and Cloud Group Discovery: Graph /users /groups roles.
[+] T1530 T1114 T1567 Cloud Storage, Email Collection, Exfil Over Web Service: SharePoint OneDrive Exchange REST.
[+] T1505.003 Web Shell: FMC home.jsp.
[+] T1059.004 Unix Shell: Netcat FIFO and /bin/sh via cmd.jar.
[+] T1572 Protocol Tunneling: SOCKS5 and reverse SSH of LDAP Kerberos SMB WinRM.
[+] T1486 Data Encrypted for Impact: Qilin after FMC recon.
[+] T1189 Drive by Compromise: inferred for CVE-2026-87491 on behavioral basis of a browser engine write with KEV evidence, not a named drive by campaign write up.
[+] T1659 Content Injection and T1185 Browser Session Hijacking: ClickFix hooks on fetch and clipboard.
[+] T1053.003 Cron: StyleSmuggler 5 minute restart.
[+] T1036.005 Masquerading: fc-cache and chronyd process names.
[+] T1136.003 Create Account Cloud Account: persistent Artifactory admins.
[+] T1562.001 Impair Defenses: AV killers in the Qilin consistent FMC cluster.
[+] T1219 Remote Access Software: ScreenConnect file execute without host confirmation.
Threat detection
SIGMA Artifactory anonymous to admin chain
SIGMA FMC package_info.pl license.tmp
SIGMA FMC Tomcat JSP write
SIGMA BlueMoon curl child of Chrome
SIGMA StyleSmuggler masquerade
YARA FMC cluster samples
YARA Artifactory Groovy plugin hunt
SIEM logic FMC LOTL and Microsoft MFA persistence
SIEM logic identity to cloud collection correlation
SIEM heuristics for MikroTik btest and NetScaler RelayState
Talos published Snort SIDs 66075 to 66080 for CVE-2026-20079, 66883 for CVE-2026-20316, and 66960 to 66961 for malware. Alert on those if you run that stack.
DEFENDER PRIORITIES
First urgency is internet reachable Secure FMC, NetScaler AAA and Gateway, FortiOS, self hosted Artifactory, ScreenConnect, MikroTik RouterOS, SonicWall SMA 1000, and PaperCut. KEV plus vendor telemetry means assume compromise until logs say otherwise, not patch and forget. Hunt Talos indicators and Wiz request sequences before you declare the hotfix successful. If FMC was exposed, treat managed firewalls, Active Directory credentials staged on the manager, and any new reverse tunnels as in scope.
[+] Patch and hunt CVE-2026-20079 and CVE-2026-20316 on every FMC before treating the box as a spectator.
[+] Patch CVE-2026-19490, CVE-2025-25249, CVE-2026-83548, CVE-2026-83549, CVE-2026-82078, CVE-2026-81578, CVE-2026-67277, and CVE-2026-86060 on exposed edge gear in the same window.
[+] Treat StyleSmuggler and Artifactory as incident response cases when the host was reachable during the exploitation windows. The fix does not evict a pre existing implant or a minted admin token.
Second is identity. Enforce phishing resistant MFA for security info registration, block device code and authentication transfer except named exceptions, and hunt Graph reconnaissance that precedes large SharePoint or mailbox pulls. Revoke sessions and strip unknown authenticator methods in the same change window. Correlate unusual sign in, new SoftwareTokenActivated or NO_DEVICE methods, Graph enumeration, and high volume SaaS downloads as one story.
[+] Storm-3121 and Storm-3032 make the sequence operational, not theoretical.
[+] Passkey themed helpdesk calls are a pretext. The audit log is the incident.
Third is Patch Tuesday triage. Ship CVE-2026-81963 and CVE-2026-85880 because they are exploited and because CVE-2026-85880 is the kernel stage of BlueMoon. Then exposed DNS, MSMQ, RRAS, Skype for Business, and other unauthenticated RCEs Microsoft marked more likely, including CVE-2026-69730. Do not pretend 113 criticals get equal labor.
[+] Force Chrome and Chromium updates past the 2026-09-03 and 2026-09-08 V8 fixes. BlueMoon compromises machines that already look patched.
[+] GTIG agentic harvesting and AA26-251A distillation are planning inputs for developer, model, and AI control plane hardening, not this week's emergency queue unless you already consume unnamed API proxies.
Fourth is RMM, ICS, and browser hygiene. ScreenConnect below 26.6.5 is an execute path through a trusted session. CISA ICS mitigations for AVEVA, Mirth Connect, Orthanc, and iDirect belong on the OT calendar. Proxmox management interfaces are now a scanned class. Devtools and Tampermonkey are an initial access path when the payload lives on docs[.]google[.]com.
RECOMMENDED ACTIONS
[+] Patch CVE-2026-20079 and CVE-2026-20316 on every Secure FMC and Security Cloud Control manager now. Do not wait for the later hardening bundle alone.
[+] Hunt FMC for home.jsp, cmd.jar, /var/tmp/license.tmp, package_info.pl --lsm, Netcat FIFOs, unexpected JARs in Tomcat webroot, init script changes, and Talos IPs 208.123.119[.]215, 89.34.96[.]56, 104.218.165[.]253, 91.214.78[.]118, 43.204.2[.]142.
[+] Deploy Talos Snort SIDs 66075 to 66080, 66883, and 66960 to 66961 if that stack is in place.
[+] Patch CVE-2026-19490 and upgrade NetScaler to 14.1-73.32 or 13.1-63.21, FIPS lines 14.1-73.32 FIPS or 13.1-37.277, then review logs for oversized unauthenticated SAML RelayState probes.
[+] Patch CVE-2025-25249 on FortiOS, FortiSwitchManager, and FortiSASE to the builds in the vendor advisory and hunt persistent outbound TLS plus unexpected Node.js on those boxes.
[+] Upgrade self hosted Artifactory to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20 or later. Delete unexpected admins matching jfrog-distribution or Nxploited_* patterns. Review logs for the 401 then 200 token minting pattern and for POST /access/api/v1/registry/join.
[+] Apply Adobe hotfix VULN-39341 for CVE-2026-75650, then rotate the Magento encryption key, admin passwords, REST SOAP GraphQL tokens, OAuth secrets, payment gateway and database credentials, SSH and deploy keys, and extension API keys.
[+] Disable ScreenConnect TransferFiles until 26.6.5 or current vendor fix is installed. Alert on wscript, cscript, mshta, and PowerShell spawned from ScreenConnect parents.
[+] Patch MikroTik RouterOS against CVE-2026-67277 and CVE-2026-86060 and remove WAN exposure of admin and btest services.
[+] Patch SonicWall SMA 1000 for CVE-2026-83548 and CVE-2026-83549 and restrict management to trusted networks.
[+] Patch PaperCut for CVE-2026-82078 and CVE-2026-81578 and review education and print server exposure.
[+] Deploy Microsoft September updates for CVE-2026-81963 and CVE-2026-85880 first, then internet exposed CVE-2026-69730 DNS and other unauthenticated RCEs Microsoft marked more likely.
[+] Force Chrome and Edge fleet updates past the V8 fixes for CVE-2026-85046 and CVE-2026-87491. Alert on curl.exe as a child of chrome.exe, msedge.exe, or chromium.exe.
[+] Audit Entra ID and Azure AD for unauthorized authentication method enrollments. Revoke suspicious methods, reset credentials, revoke sessions and refresh tokens, and review mailbox rules.
[+] Enforce Conditional Access with phishing resistant MFA and managed devices for Exchange, SharePoint, and Graph privileged apps. Put strict controls on security info registration.
[+] Block device code and auth transfer flows except where business justified. Restrict user consent. Require admin approval for Mail.Read, Files.Read.All, and Directory.Read.All.
[+] Enable Microsoft Graph activity logs and mailbox auditing. Alert on directory enumeration, auth method registration, and high volume file or mail access.
[+] Restrict Tampermonkey and javascript: URL pastes on managed browsers. Alert on Visualization API /gviz/tq fetches unrelated to known Sheets use. Monitor docs[.]google[.]com requests from non Docs contexts.
[+] Implement AI model canary prompts, 30 to 50 fixed and graded, hourly against production endpoints. Add model quality and substitution alerts to incident notification clauses. Avoid unnamed API proxies and aggregators.
[+] Deploy detections from the Microsoft Cloud Web Applications Threat Matrix and protect logging configs from tampering.
[+] Apply CISA ICS mitigations for AVEVA Pipeline Integrity Monitor, NextGen Mirth Connect, Orthanc DICOM, and ST Engineering iDirect. Segment OT networks.
[+] Treat Proxmox management interfaces as critical attack surface: authenticate, segment, monitor.
[+] Review N-able N-central against CVE-2026-86218.
[+] Restrict outbound connections from management plane appliances to non approved jump hosts on ports 22, 1080, 445, 5985, and 88 unless explicitly required.
[+] Healthcare and health tech teams should rotate vendor and third party API credentials after the AdaptHealth, CareCloud, and Veradigm disclosure cluster, especially for AWS hosted EHR environments.
CONFIDENCE & LIMITATIONS
Item | Confidence | Rationale |
|---|---|---|
CVE-2026-20079 exploitation and KEV | High | Vendor telemetry plus catalog listing |
UAT-12197 FMC webshell and JAR | High | Vendor described artifacts and hashes |
UAT-11823 Cyclops Blink overlap | Elevated | High confidence vendor cluster, Sandworm link is prior US UK family attribution not a fresh joint advisory |
UAT-11988 Qilin consistent activity | Elevated | High confidence vendor behavioral assessment, not a courtroom identity |
Artifactory chain CVE-2026-42016 CVE-2026-42018 CVE-2026-82329 | High | Vendor confirmed chain, IOCs, later KEV on the pair |
BlueMoon kit and APT31 first use | Elevated | Multi cluster vendor tracking, China nexus for later crews is majority suspected |
CVE-2026-81963 and CVE-2026-85880 exploited | High | Vendor plus KEV plus multiple consulted outlets |
AA26-251A distillation naming | High | Three agency joint advisory |
Passkey to Graph sequence | Elevated | Primary vendor telemetry, single vendor campaign write up |
CVE-2026-19490 in the wild | Elevated | KEV and probe telemetry, no confirmed successful compromise |
StyleSmuggler CVE-2026-75650 exploitation | High | Pre hotfix exploitation plus implant behavior in consulted sources |
ScreenConnect CVE-2026-84869 abuse | Elevated | KEV plus multiple incident write ups |
MikroTik KEV status | High | Catalog listing |
MikroTrick operational color | Lower | Detail sits outside the strongest vendor set |
PivotC2 on CVE-2025-25249 | Lower | Secondary reporting, actor under attribution |
Storm-3121 and Storm-3032 | Elevated | Microsoft named for the initial access pattern, not every downstream case |
GTIG agentic harvesting | Elevated | Quarterly tradecraft published this week, not a fresh single incident |
PaperCut and SMA 1000 exploitation | Elevated | Consulted sources plus advisories |
GitLab critical path traversal KEV status | Lower | Consulted sources diverged |
Healthcare disclosure figures | Mixed | Confirmed filings for AdaptHealth and CareCloud, Veradigm count is an attacker claim |
ShinyHunters McKesson and Florida driver claims | Low | Attacker self attribution, unnamed orgs did not confirm |
Interlock NFM Lending claim | Low | Attacker claim only |
GemStone and ShadowPad as BlueMoon payloads | Low | Single source, unconfirmed |
Full victim scope of FMC and Artifactory | Unknown | Not published |
