“Eye” spy: Cyclops Blink returns with extended capabilities
2026-09-11T20:51:32Z•e5757a01db7e0ffb67bc9aa34ef5ca5c26f3ace7d2be58f3dc8ce319a46da283
CVE-2026-83548CVE-2026-83549AI impersonationCisco FMCCyclops BlinkGOLD SHERWOODPHP web serverPatch TuesdaySonicWall SMA1000active exploitationfirewall appliancesmalwarephishingransomwarerootkitvulnerability management
What happened
Sophos security intelligence feed covering a Cyclops Blink malware campaign targeting Cisco Firewall Management Center devices, a PHP web-server rootkit, SonicWall SMA1000 vulnerabilities reportedly under active exploitation, ransomware activity linked to GOLD SHERWOOD affiliates, AI-brand impersonation malware campaigns, and broader vulnerability and ransomware trends.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- e5757a01db7e0ffb67bc9aa34ef5ca5c26f3ace7d2be58f3dc8ce319a46da283
- Enrichment time
- 2026-09-11T20:51:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.