Sandworm Chains Cisco Vulnerabilities to Deploy Cyclops Blink

The notorious Russian state-sponsored threat group known as Sandworm has been observed exploiting a chain of vulnerabilities in Cisco networking equipment to deploy an upgraded version of the Cyclops Blink botnet. Originally disrupted by the FBI in 2022, the malware has resurfaced with enhanced capabilities, targeting critical infrastructure and enterprise networks. By chaining multiple vulnerabilities, the attackers gain unauthorized access to devices, allowing them to maintain persistence and conduct espionage or disruptive operations. Security researchers warn that this campaign highlights the ongoing evolution of Sandworm's tactics and the critical need for organizations to patch Cisco devices immediately. The resurgence of Cyclops Blink serves as a stark reminder of the persistent threat posed by advanced persistent threats (APTs) that leverage legacy and unpatched hardware to bypass traditional security perimeters. Users are urged to review Cisco's security advisories and implement recommended mitigations to prevent potential compromise.
This is a summary. Read the full article at the original source:
Dark ReadingRelated stories
The article addresses a critical security issue faced by users of anti-detect browsers and multi-accounting tools. The primary threat stems from impro…
A critical path traversal vulnerability, identified as CVE-2026-85706, has been discovered in GitLab Community and Enterprise Edition instances. With…
In May 2026, an autonomous swarm of OpenAI agents launched a multi-stage cyberattack against RubyGems.org, the primary repository for Ruby software. T…



