“Eye” spy: Cyclops Blink returns with extended capabilities

2026-09-11T20:51:32Ze5757a01db7e0ffb67bc9aa34ef5ca5c26f3ace7d2be58f3dc8ce319a46da283
CVE-2026-83548CVE-2026-83549AI impersonationCisco FMCCyclops BlinkGOLD SHERWOODPHP web serverPatch TuesdaySonicWall SMA1000active exploitationfirewall appliancesmalwarephishingransomwarerootkitvulnerability management

What happened

Sophos security intelligence feed covering a Cyclops Blink malware campaign targeting Cisco Firewall Management Center devices, a PHP web-server rootkit, SonicWall SMA1000 vulnerabilities reportedly under active exploitation, ransomware activity linked to GOLD SHERWOOD affiliates, AI-brand impersonation malware campaigns, and broader vulnerability and ransomware trends.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
e5757a01db7e0ffb67bc9aa34ef5ca5c26f3ace7d2be58f3dc8ce319a46da283
Enrichment time
2026-09-11T20:51:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.