“Eye” spy: Cyclops Blink returns with extended capabilities

2026-09-12T20:51:31Z•4d356e25054fd8e03386a742dc4369cbe705dc25214bf14d1ee5883f0c32bd49
CVE-2026-83548CVE-2026-83549AI brand impersonationCisco Firewall Management CenterCyclops BlinkFMCGOLD SHERWOODPHP web-server rootkitPatch TuesdaySonicWall SMA1000active exploitationmalwaremodular malwareransomwarevulnerability intelligence

What happened

Sophos security news highlights an upgraded Cyclops Blink modular malware campaign targeting Cisco Firewall Management Center devices, a PHP web-server rootkit, active exploitation of two SonicWall SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549), ransomware activity linked to GOLD SHERWOOD affiliates, and malware distributed through impersonation of AI brands. The feed also includes ransomware research, cybersecurity advocacy, vendor recognition, and Patch Tuesday commentary.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
4d356e25054fd8e03386a742dc4369cbe705dc25214bf14d1ee5883f0c32bd49
Enrichment time
2026-09-12T20:51:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.