TL;DR
Cisco Secure FMC authentication bypass is under active attack today. A new exploit kit (BlueMoon) chaining Chrome and Windows flaws is deployed by four espionage-linked threat groups. AI user credentials are being stolen via infostealer malware to bypass MFA on AI service accounts. Patch Cisco FMC, rotate AI API keys, and enable hardware MFA immediately.
Executive Summary
- Cisco Secure Firewall Management Center (FMC) vulnerability CVE-2026-20079 is being actively exploited in real-world attacks.
- Four China-aligned cyber-espionage groups are deploying a previously undocumented exploit kit called BlueMoon that chains Windows and Chrome vulnerabilities together.
- Information stealer malware (Lumma Stealer, Vidar) is harvesting AI service credentials and authentication tokens that can bypass MFA from platforms including Google, Anthropic, and others.
- U.S. authorities disrupted the Xinbi Guarantee scam marketplace and seized $52.8 million in cryptocurrency from 52 wallets.
- Healthcare breach at AdaptHealth exposed data of 4.1 million people; breach attributed to ShinyHunters threat group.
Top Threats Today
1. Cisco Secure FMC Authentication Bypass Under Active Attack
Severity: CRITICAL Affected: Technology
Cisco has confirmed that CVE-2026-20079, a maximum-severity authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) software, is being actively exploited in attacks [1]. The vulnerability allows unauthenticated access to the FMC console, a critical security control point in enterprise networks. Organizations running vulnerable FMC instances are at immediate risk of unauthorized access to firewall configurations and network monitoring data.
Sources:[1] BleepingComputer
Recommended Action
- Apply Cisco's security patch for CVE-2026-20079 immediately to all Secure FMC deployments
- Review FMC access logs for unauthorized authentication attempts or console access from unexpected IP ranges
- Restrict FMC management interface access to trusted networks using network-level controls (ACLs, VPN-only access)
- If patching cannot be completed immediately, enable additional logging and monitoring on FMC authentication events
2. BlueMoon Exploit Kit: Four APT Groups Targeting Chrome and Windows
Severity: HIGH Affected: Technology
Multiple espionage-motivated threat activity clusters have deployed a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome [1]. At least four China-aligned cyber-espionage groups are using the same exploit kit within days of each other, indicating either shared tooling or coordinated reconnaissance activity [1]. The first in-the-wild use of BlueMoon has been attributed to China-aligned threat actors [1]. This represents a significant escalation in the sophistication and coordination of state-sponsored campaigns targeting enterprise endpoints.
Sources:[1] The Hacker News
Recommended Action
- Ensure Windows and Chrome are updated to the latest versions; prioritize systems in government, defense, and finance sectors
- Implement application whitelisting and Endpoint Detection and Response (EDR) on all endpoints to detect exploit kit execution chains
- Monitor for suspicious process chains involving Windows system binaries and Chrome renderer processes
- Conduct vulnerability scans to identify unpatched Windows and Chrome instances in your environment
3. AI Account Credential Theft via Infostealer Malware; MFA Bypass
Severity: HIGH Affected: Technology
Cybercriminals are harvesting artificial intelligence user account credentials and replayable authentication tokens via information stealer malware (Lumma Stealer, Vidar) to gain illicit access to AI service accounts from model providers including Google, Anthropic, and others [1]. The harvested tokens can bypass multi-factor authentication, granting attackers persistent access to AI platforms and the ability to use or exfiltrate AI models ⚠ [1]. This attack vector directly undermines MFA as a security control for AI infrastructure and creates risk of unauthorized use of generative AI services, potential model exfiltration, and unauthorized API consumption charges.
Sources:[1] The Hacker News
Recommended Action
- Rotate all AI service API keys and authentication tokens immediately; regenerate credentials in Google Cloud, Anthropic, OpenAI, and other AI provider consoles
- Implement hardware-based MFA (security keys, hardware tokens) on AI service accounts; SMS and app-based MFA can be bypassed via token theft
- Scan endpoints for information stealer malware (Lumma, Vidar, RedLine) using EDR and malware scanning tools
- Monitor AI service API logs for unusual access patterns, geographic anomalies, or high API consumption rates
- Restrict AI service API key usage to specific IP ranges and API endpoints where possible
4. U.S. Disrupts Xinbi Guarantee Scam Marketplace; $numerous Seized
Severity: MEDIUM Affected: Technology
The U.S. Department of Justice announced coordinated enforcement actions against Xinbi Guarantee, an illicit online marketplace offering scam services [1]. The operation resulted in seizure of Telegram channels used to operate the service and confiscation of $52.8 million in cryptocurrency from 52 wallets connected ⚠ to the platform [1][2]. This operation targets the cyber-scam economy infrastructure but does not address underlying infostealer and phishing campaigns that feed stolen credential marketplaces.
Sources:[1] The Hacker News[2] The Record
Recommended Action
- Monitor for Telegram channels and dark web marketplaces advertising stolen credential sales; report URLs to FBI's IC3 or local law enforcement
- Review identity theft monitoring and credit freeze services for personal and corporate executives
- Increase vigilance for phishing and credential-harvesting campaigns targeting employee inboxes
5. AdaptHealth Breach Exposes 4.1 Million People; ShinyHunters Attributed
Severity: HIGH Affected: Healthcare
Healthcare company AdaptHealth confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July and attributed to the ShinyHunters threat group [1]. The breach exposed personal health information tied to medical device users and patients. This represents a significant breach in the healthcare sector and reinforces ongoing risk from the ShinyHunters extortion-focused threat group.
Sources:[1] BleepingComputer
Recommended Action
- If you are an AdaptHealth customer or patient, enroll in the offered credit monitoring and identity theft protection services
- Monitor health insurance accounts and medical device vendor accounts for unauthorized access
- Healthcare organizations: review vendor security assessments for third-party service providers and mandate breach notification timelines in contracts
Today’s Action Checklist
- ☐ URGENT: Patch Cisco Secure FMC CVE-2026-20079 on all systems; apply network-level access restrictions if immediate patching is not possible
- ☐ URGENT: Rotate all AI service API keys and authentication tokens; implement hardware-based MFA on AI platform accounts
- ☐ HIGH: Update Windows and Google Chrome to latest versions; scan for and remove Lumma Stealer, Vidar, and other information stealer malware
- ☐ HIGH: Review and test EDR/SIEM detection rules for BlueMoon-style Windows+Chrome exploit chains
- ☐ MEDIUM: If AdaptHealth customer: enroll in identity theft protection; monitor health insurance and medical device accounts