Secret CISO 9/14: 347K Trezor Phish, Cisco FMC Rooted, Citrix Bypass, Totolink PoCs
A third-party email vendor incident triggers 347K Trezor phishing blasts, Cisco FMC is getting rooted in the wild by multiple clusters, Citrix NetScaler auth bypass sits in KEV, and Totolink router PoCs drop today. Plus: LLM access resale and passkey-themed lures.
Identity is still the shortest path to impact, but this week’s twist is the “second-order breach”: vendors, management planes, and test environments turning into production-grade problems. Also, your patch queue is now a threat actor’s sprint backlog.
Today's Top 5
- 347,000 Trezor users phished: A breached email provider let attackers blast convincing “security alert” lures at scale. The payload is designed to make the victim hand over the one secret that never forgives.
- Cisco FMC gets rooted in the wild: Three distinct clusters are chaining an auth bypass into credential theft and ransomware staging. If your firewall manager is internet-facing, it is already a story.
- Citrix NetScaler auth bypass in KEV: The alternate-path login bypass is one of those bugs you only need once. The awkward part is how many Gateway deployments look exactly like the vulnerable config.
- Surfshark test server exposed: A misconfigured internal environment became reachable from the internet, and an attacker touched it. The phrase “no user data impacted” can still hide a lot of operational risk.
- Totolink router PoCs drop: New A3002MU issues ship with public exploit code and high scores. Cheap edge devices keep acting like free initial access brokers.
Now let’s do the uncomfortable part: what to patch, what to hunt, and what to assume was already touched.
Data Breaches

- Trezor customers targeted after Brevo breach: Hardware wallet maker Trezor said attackers abused its email provider Brevo to send roughly 347,000 phishing emails that push a fake app and try to steal wallet backup credentials. Brevo said attackers accessed 138 accounts due to access being wrongly scoped across reachable organizations. Source: TechCrunch
- Surfshark discloses misconfigured internal server access: Surfshark said a human error exposed an internal engineering test server to the internet, and a threat actor accessed limited engineering material plus build-related credentials that were rotated. The company says production VPN systems and user data were not affected, but the incident is a reminder that “test” often contains real secrets. Source: BleepingComputer
- NFM Lending listed by Interlock ransomware group: Threat intel trackers report the Interlock ransomware group posted NFM Lending as a claimed victim, with allegations of large-scale data theft. As of the latest public reporting, this remains a leak-site claim rather than a confirmed disclosure by the company. Source: SOCRadar
- US law firms targeted in Luna Moth extortion campaign: A new report details Luna Moth, also tracked as Silent Ransom Group, using phone-based social engineering and “USB extortion” tactics against the US legal sector, with at least one firm reportedly confirming a breach to a state regulator. If your firm treats voice as trusted, this is your warning label. Source: Wasteland
Security Research

- Cisco FMC exploitation: multiple clusters, one management plane: Reporting says CVE-2026-20079 is being weaponized to bypass authentication in Cisco Secure Firewall Management Center, with activity tied to Qilin affiliates and other clusters. The key risk is that FMC is a policy and credential hub, so compromise becomes a network-wide force multiplier. Source: CyberSecureToday
- SANS: self-expanding stolen LLM access supply chain: The SANS Stormcast highlights a diary on AI agents harvesting and re-serving access to LLM inference gateways, plus passkey-themed social engineering and a PAN-OS item. It reads like a preview of “credential stuffing, but for model access.” Source: SANS ISC
- Proofpoint on mega credential leaks and how attackers connect the dots: Proofpoint published a new deep dive into the “24B credentials” exposure story and why it keeps paying off for attackers, including the workflow from stolen passwords to account takeover. Useful ammunition for getting buy-in on MFA, session controls, and credential hygiene that actually sticks. Source: Proofpoint
- Totolink A3002MU: new remote memory corruption issues with public PoCs: New Totolink router vulnerabilities are surfacing with public exploit writeups. If your exposure management ignores SMB and consumer-grade routers, attackers will keep using them as cheap pivots into real networks. Source: SecNews
- Citrix NetScaler auth bypass: government guidance updates: Canada’s Cyber Centre issued an updated alert for NetScaler ADC and Gateway flaws, including CVE-2026-19490 authentication bypass using an alternate path or channel. It is a clean checklist-style document for leadership and operators. Source: Canadian Centre for Cyber Security
Top CVEs
- CVE-2026-20079: Cisco Secure Firewall Management Center authentication bypass that can lead to root-level command execution on a high-value management plane. CISA lists it as exploited, and multiple clusters are reported chaining it for credential access and ransomware staging. Source
- CVE-2026-19490: Citrix NetScaler ADC and NetScaler Gateway authentication bypass using an alternate path or channel, impacting Gateway and AAA virtual server configurations. It is in CISA KEV, so treat internet-exposed appliances as already under active interest. Source
- CVE-2026-87491: Google Chromium V8 out-of-bounds write, exploited in the wild, enabling code execution within the browser sandbox via crafted HTML. The real-world risk is chaining with privilege escalation to break out and persist. Source
- CVE-2025-25249: Fortinet heap-based buffer overflow affecting FortiOS and FortiSwitchManager, listed by CISA as exploited. This is the kind of edge device flaw that quietly becomes mass scanning fuel. Source
- CVE-2026-85880: Windows ALPC local privilege escalation via heap-based buffer overflow, listed as actively exploited and fixed in September 2026 updates. Watch for it as the “finish the chain” step after initial code execution. Source
Podcasts & Talks

- SANS Stormcast (Sep 14, 2026): Self-expanding stolen LLM gateways, PAN-OS, passkey lures: A tight daily briefing with pragmatic takeaways on credential resale for LLM access and social engineering that targets modern authentication. Good listening for anyone trying to explain why “passkeys” still need process. Listen: SANS ISC
Final Words
Today’s pattern is not subtle. Attackers want control points: the thing that emails your customers, the thing that manages your firewalls, the thing your admins use to “just quickly test something.”
If you are a CISO, you do not need more awareness posters. You need tighter vendor blast radius, fewer internet-exposed management planes, and faster proof that the patch actually landed on the right box.
If this edition helped you, forward it to one colleague who owns patching, identity, or vendor risk. If you’re reading this on the web because someone forwarded it, subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!