“Eye” spy: Cyclops Blink returns with extended capabilities
2026-09-12T20:51:31Z•4d356e25054fd8e03386a742dc4369cbe705dc25214bf14d1ee5883f0c32bd49
CVE-2026-83548CVE-2026-83549AI brand impersonationCisco Firewall Management CenterCyclops BlinkFMCGOLD SHERWOODPHP web-server rootkitPatch TuesdaySonicWall SMA1000active exploitationmalwaremodular malwareransomwarevulnerability intelligence
What happened
Sophos security news highlights an upgraded Cyclops Blink modular malware campaign targeting Cisco Firewall Management Center devices, a PHP web-server rootkit, active exploitation of two SonicWall SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549), ransomware activity linked to GOLD SHERWOOD affiliates, and malware distributed through impersonation of AI brands. The feed also includes ransomware research, cybersecurity advocacy, vendor recognition, and Patch Tuesday commentary.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 4d356e25054fd8e03386a742dc4369cbe705dc25214bf14d1ee5883f0c32bd49
- Enrichment time
- 2026-09-12T20:51:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.