// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
Breach Record

Cisco

DISCLOSED 2026-09-12 · RANSOMWARE · RANSOMWARE

Cisco Talos has attributed exploitation of firewall vulnerability CVE-2026-20079 to three threat groups, who use custom antivirus tools before deploying Qilin ransomware on selected endpoints. The attack begins with a corporate firewall compromise, and victims may only become aware upon receiving a ransom notification. Cisco recommends applying hotfixes and updating...

The record

What we know

Disclosed
2026-09-12
Attack vector
Ransomware
RANSOMWARE
Sources

Cited reporting

Similar vector · recent

Other ransomware breaches on file

This page is the permanent ColdRecon entry for the Cisco disclosure. It updates if new public reporting emerges. All tracked breaches →

Cisco just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →