Security news

Latest security news

39 of 1,256 storiesCiscoClear all

Thu, 10 Sept 2026

  1. We've got one word for it, and it's usually the wrong one

    In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.

    Cisco Talos
  2. Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

    Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.

    BleepingComputerCisco
  3. Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

    State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabilities under active attack “Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software,” the company’s researchers confirmed on Wednesday. These are the above mentioned CVE-2026-20079 and CVE-2026-20316, which Cisco flagged … More →

    CriticalUsed in attacksHelp Net SecurityCisco
  4. CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

    CriticalThe Hacker NewsCitrix, Cisco, Fortinet
  5. Organizations Warned of Cisco Secure FMC Exploitation

    Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

    CriticalSecurityWeekCisco

Wed, 9 Sept 2026

  1. Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

    Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.

    CriticalBleepingComputerCisco
  2. Cisco security advisory (AV26-197) – Update 3

    Serial number: AV26-197 Date: March 5, 2026 Updated: September 9, 2026 On March 4, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Cisco Security Cloud Control (SCC) Firewall Management – all versions Cisco Secure Firewall Management Center (FMC) – all versions Cisco Secure Firewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions Update 1 On March 18, 2026, Cisco stated that CVE-2026-20131 is being actively exploited. Update 2 On March 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20131 to their Known Exploited Vulnerabilities (KEV) Database. Update 3 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available. Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability Cisco Secure Firewal

    CriticalUsed in attacksCanadian Centre for Cyber SecurityCisco
  3. Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

    Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.

    Cisco TalosCisco

Tue, 8 Sept 2026

  1. Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

    Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."

    Cisco TalosMicrosoft
  2. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.

    Cisco Talos

About this news

1,256
Stories
40
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets