Skip to content
Cisco FMC actively exploited; BlueMoon exploit kit chains Chrome & Windows; AI tokens bypass MFA

Cisco FMC actively exploited; BlueMoon exploit kit chains Chrome & Windows; AI tokens bypass MFA

Defendwork defend.network September 10, 2026

Cisco Secure FMC authentication bypass is under active attack today. A new exploit kit (BlueMoon) chaining Chrome and Windows flaws is deployed by four espionage-linked threat groups. AI user credentials are being stolen via infostealer malware to bypass MFA on AI service accounts. Patch Cisco FMC, rotate AI API keys, and enable hardware MFA immediately.

Cisco Secure Firewall Management Center (FMC) vulnerability CVE-2026-20079 is being actively exploited in real-world attacks.

Four China-aligned cyber-espionage groups are deploying a previously undocumented exploit kit called BlueMoon that chains Windows and Chrome vulnerabilities together.

Information stealer malware (Lumma Stealer, Vidar) is harvesting AI service credentials and authentication tokens that can bypass MFA from platforms including Google, Anthropic, and others.

U.S. authorities disrupted the Xinbi Guarantee scam marketplace and seized $52.8 million in cryptocurrency from 52 wallets.

Healthcare breach at AdaptHealth exposed data of 4.1 million people; breach attributed to ShinyHunters threat group.

1. Cisco Secure FMC Authentication Bypass Under Active Attack

Severity: CRITICAL Affected: Technology

Cisco has confirmed that CVE-2026-20079, a maximum-severity authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) software, is being actively exploited in attacks [1] . The vulnerability allows unauthenticated access to the FMC console, a critical security control point in enterprise networks. Organizations running vulnerable FMC instances are at immediate risk of unauthorized access to firewall configurations and network monitoring data. Sources: [1] BleepingComputer

Apply Cisco's security patch for CVE-2026-20079 immediately to all Secure FMC deployments

Review FMC access logs for unauthorized authentication attempts or console access from unexpected IP ranges

Restrict FMC management interface access to trusted networks using network-level controls (ACLs, VPN-only access)

If patching cannot be completed immediately, enable additional logging and monitoring on FMC authentication events

2. BlueMoon Exploit Kit: Four APT Groups Targeting Chrome and Windows

Severity: HIGH Affected: Technology

Multiple espionage-motivated threat activity clusters have deployed a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome [1] . At least four China-aligned cyber-espionage groups are using the same exploit kit within days of each other, indicating either shared tooling or coordinated reconnaissance activity [1] . The first in-the-wild use of BlueMoon has been attributed to China-aligned threat actors [1] . This represents a significant escalation in the sophistication and coordination of state- campaigns targeting enterprise endpoints. Sources: [1] The Hacker News

Ensure Windows and Chrome are updated to the latest versions; prioritize systems in government, defense, and finance sectors

Implement application whitelisting and Endpoint Detection and Response (EDR) on all endpoints to detect exploit kit execution chains

Monitor for suspicious process chains involving Windows system binaries and Chrome renderer processes

Conduct vulnerability scans to identify unpatched Windows and Chrome instances in your environment

3. AI Account Credential Theft via Infostealer Malware; MFA Bypass

Severity: HIGH Affected: Technology

Cybercriminals are harvesting artificial intelligence user account credentials and replayable authentication tokens via information stealer malware (Lumma Stealer, Vidar) to gain illicit access to AI service accounts from model providers including Google, Anthropic, and others [1] . The harvested tokens can bypass multi-factor authentication, granting attackers persistent access to AI platforms and the ability to use or exfiltrate AI models ⚠ [1] . This attack vector directly undermines MFA as a security control for AI infrastructure and creates risk of unauthorized use of generative AI services, potential model exfiltration, and unauthorized API consumption charges. Sources: [1] The Hacker News

Rotate all AI service API keys and authentication tokens immediately; regenerate credentials in Google Cloud, Anthropic, OpenAI, and other AI provider consoles

Implement hardware-based MFA (security keys, hardware tokens) on AI service accounts; SMS and app-based MFA can be bypassed via token theft

Scan endpoints for information stealer malware (Lumma, Vidar, RedLine) using EDR and malware scanning tools

Monitor AI service API logs for unusual access patterns, geographic anomalies, or high API consumption rates

Restrict AI service API key usage to specific IP ranges and API endpoints where possible

4. U.S. Disrupts Xinbi Guarantee Scam Marketplace; $numerous Seized

Severity: MEDIUM Affected: Technology

The U.S. Department of Justice announced coordinated enforcement actions against Xinbi Guarantee, an illicit online marketplace offering scam services [1] . The operation resulted in seizure of Telegram channels used to operate the service and confiscation of $52.8 million in cryptocurrency from 52 wallets connected ⚠ to the platform [1] [2] . This operation targets the cyber-scam economy infrastructure but does not address underlying infostealer and phishing campaigns that feed stolen credential marketplaces. Sources: [1] The Hacker News [2] The Record

Monitor for Telegram channels and dark web marketplaces advertising stolen credential sales; report URLs to FBI's IC3 or local law enforcement

Review identity theft monitoring and credit freeze services for personal and corporate executives

Increase vigilance for phishing and credential-harvesting campaigns targeting employee inboxes

5. AdaptHealth Breach Exposes 4.1 Million People; ShinyHunters Attributed

Severity: HIGH Affected: Healthcare

Healthcare company AdaptHealth confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July and attributed to the ShinyHunters threat group [1] . The breach exposed personal health information tied to medical device users and patients. This represents a significant breach in the healthcare sector and reinforces ongoing risk from the ShinyHunters extortion-focused threat group. Sources: [1] BleepingComputer

If you are an AdaptHealth customer or patient, enroll in the offered credit monitoring and identity theft protection services

Monitor health insurance accounts and medical device vendor accounts for unauthorized access

Healthcare organizations: review vendor security assessments for third-party service providers and mandate breach notification timelines in contracts

Today’s Action Checklist

☐ URGENT: Patch Cisco Secure FMC CVE-2026-20079 on all systems; apply network-level access restrictions if immediate patching is not possible

☐ URGENT: Rotate all AI service API keys and authentication tokens; implement hardware-based MFA on AI platform accounts

☐ HIGH: Update Windows and Google Chrome to latest versions; scan for and remove Lumma Stealer, Vidar, and other information stealer malware

☐ HIGH: Review and test EDR/SIEM detection rules for BlueMoon-style Windows+Chrome exploit chains

☐ MEDIUM: If AdaptHealth customer: enroll in identity theft protection; monitor health insurance and medical device accounts