SAMURAI CYBER WATCH

Issue #14 — July 31, 2026

Practical Cyber Intelligence for Business Leaders in Non-Superpower Nations

THIS WEEK'S BRIEFING

Cisco FMC Zero-Day — The Command Center of Your Perimeter Defense Is Under Attack With No Patch Available

Cisco discloses an actively exploited zero-day in Firewall Management Center with no fix in sight. APT-C-60's campaign against Japan continues unabated. A SAML bypass in SolarWinds Web Help Desk brings back memories of 2020. This week's incidents share one thread: the infrastructure defenders rely on is becoming the target.

THE KEY DEVELOPMENT

CISCO FMC ZERO-DAY: THE HEART OF YOUR PERIMETER DEFENSE IS UNDER ATTACK RIGHT NOW

On July 30, 2026, Cisco disclosed an actively exploited zero-day vulnerability in Cisco Secure Firewall Management Center. According to Cisco Security Advisory cisco-sa-fmc-zero-day-2026-0730, a CVE identifier is still pending formal assignment, and no patch is currently available. Think of the FMC as the command center for an organization's entire network perimeter defense. The fact that this command center is now being compromised with no fix in sight is, when you stop and consider it, deeply serious.

If FMC is breached, an attacker gains the ability to rewrite firewall policies across all managed devices at will. What makes this especially noteworthy is that Cisco itself explicitly states in the advisory that combining this vulnerability with others can amplify the damage. The implication is clear: this flaw is highly likely to serve as the entry point for chained, multi-stage attacks. Having worked in this industry for over two decades, I can say with confidence that zero-days in management infrastructure almost never result in isolated incidents. They become the launchpad for follow-on attacks virtually without exception.

Organizations running Cisco FMC in enterprise environments should check Cisco's official security advisory page immediately, apply all available workarounds, and increase monitoring. Until a full patch is released, strictly limit access to the FMC management interface to only the specific endpoints and IP addresses required for legitimate business operations. Continuously monitor for anomalous network traffic, unexpected access attempts to FMC, and any suspicious entries in policy change logs. These are the most realistic defensive measures available right now.

JAPAN LENS: THE PERSISTENCE OF APT-C-60 AND THE REALITY WE MUST CONFRONT

This week, the incident that deserves the most serious attention is not the Cisco FMC zero-day. It is the targeted espionage campaign against Japanese organizations by APT-C-60, the continuation of which was officially confirmed by JPCERT/CC in 2026. Considerable time has passed since JPCERT/CC first publicly warned about this group's activity, and the attacks have not stopped. That continuity is, in my view, the most alarming signal of the week.

Look closely at the tradecraft. The group is abusing Proton Drive, GitHub, GitLab, jsDelivr, and Codeberg as command-and-control infrastructure. These are precisely the platforms that security teams have placed on allowlists as legitimate business services. Deliberately selecting services that are difficult to block technically demonstrates a thorough understanding of how defenders operate. This should not be read merely as a tooling choice. It is a direct challenge to defensive philosophy itself.

The version progression of their spyware, SpyGlace, from v3.1.15 to v3.1.18, also warrants attention. Minor version increments over a short period plainly indicate that detection evasion improvements are being made on an ongoing basis. Sustaining this level of development investment is not possible without state or state-level backing.

If any Japanese organization still operates under the assumption that it is not a target, that assumption is itself the greatest risk. Recruiters, researchers, and staff involved in policy-related functions should be designated as the highest-priority recipients of spear-phishing training, starting now. The behavioral patterns of this group repeatedly demonstrate that state-level threat actors do not limit their targeting to technical departments.

BEYOND THE EPICENTER: THE REALITY FACING SMES AND EDUCATIONAL INSTITUTIONS

This week's ransomware attack on Shin FA Com carries a clear message for executives at small and mid-sized manufacturers and logistics companies. The company specializes in factory automation equipment and robotic systems, making it deeply embedded within supply chains. It may not be a household name, but that positioning is precisely what makes it valuable to attackers. Concern exists regarding potential impact on OT environments, and a production line shutdown is not merely a financial loss — it directly affects trust relationships with business partners. The belief that being small means being safe is aligned with exactly how attackers prefer to select their targets. That gap in perception needs to close.

The ransomware attack on Hachioji Gakuen also cannot be overlooked. Educational institutions hold large volumes of personal data belonging to students, parents, and staff, yet their security budgets are severely limited compared to those of commercial enterprises. Attackers calculate that gap before choosing their targets. It is precisely because budgets are constrained that prioritizing what to protect becomes even more critical. This is not a challenge unique to schools. It applies to every organization operating under budget restrictions.

The exposure of personal information through an external vulnerability in the Life Insurance Association of Japan's policy inquiry system was not the result of an external attack. It was exposure caused by flaws in system design and operations. A configuration error in an outsourced system becomes the responsibility of the organization that commissioned it. If any organization has been treating security verification of third-party vendors as the vendor's problem alone, this week's incident should serve as a clear opportunity to correct that assumption.

STATE ACTOR WATCH: WHAT PRECISION AND PERSISTENCE REVEAL

Two incidents this week carry strong indicators of state involvement.

The APT-C-60 campaign against Japanese organizations was covered in detail in the Japan Lens section, but it is worth restating here. The continuity, precision, and sophistication of the group's infrastructure cannot be sustained without state or state-level organizational backing. A standalone criminal group would have no economic rationale for persistently targeting organizations in a specific region over this extended a period. The technique of combining multiple legitimate cloud services as C2 infrastructure demonstrates advanced operational security specifically designed to evade detection through traffic analysis. The weight of JPCERT/CC's formal 2026 confirmation that this activity is ongoing should be shared across your organization.

The second incident involves a critical SAML authentication bypass vulnerability in SolarWinds Web Help Desk. The moment the SolarWinds name appears, many readers will recall the 2020 supply chain attack. Given how state-level actors exploited SolarWinds products in that incident, the implications of a SAML authentication bypass cannot be treated lightly. In single sign-on environments, a single successful compromise opens the door to broad lateral movement. Organizations running SolarWinds WHD in enterprise environments should apply the available patch immediately and review indicators of compromise, with past lessons firmly in mind.

DEFEND WITHOUT CHOOSING SIDES

Practical defensive actions drawn from this week's incidents

① Every organization operating Cisco FMC should immediately check Cisco's official security advisory page and apply all available workarounds. Restrict access to the FMC management interface to only the endpoints and IP addresses required for legitimate business operations, and begin real-time monitoring of policy change logs. Because this is a zero-day with no patch yet available, hardening access controls must be your first move — not waiting.

② Organizations that own or have outsourced web applications built on Ruby on Rails should identify versions affected by KindaRails2Shell and treat upgrading to the latest version as a top-priority task. Given that WAF-based mitigation is reported to be unreliable against this vulnerability, patching is the only fundamental fix. Do not neglect to request version confirmation from any third-party vendors managing your applications.

③ Review communication logs from your environment to Proton Drive, GitHub, GitLab, jsDelivr, and Codeberg this week as a countermeasure against APT-C-60. Access to these legitimate services is not inherently suspicious in itself, but connections originating from non-IT department endpoints, or small periodic data transfers during late-night hours, merit close examination. Begin planning spear-phishing training exercises now, with recruiting and research departments as the primary target groups.

④ Organizations using SolarWinds Web Help Desk should apply the SAML authentication bypass patch on an emergency basis and conduct a thorough review of authentication logs from the past 30 days. Look specifically for logins at unusual hours and any administrative actions performed by users who would not ordinarily have access. As the 2020 incident demonstrated, attacks against SolarWinds products tend to go undetected for extended periods. Prioritizing early detection is essential.

⑤ Ensure that the recent large batch of Google Chrome patches has been applied across your organization. Do not leave this to end users and automatic updates. In enterprise-managed environments, verify your Chrome version policy this week and confirm that all critical fixes have been deployed to every endpoint. Unpatched browsers used daily for business represent an easy entry point for attackers. It is consistent execution of these fundamentals — not dramatic zero-day response — that actually prevents the greatest number of breaches.

NEXT ISSUE

Next week, we continue tracking the evolving threat landscape — including any patch release for the Cisco FMC zero-day and further developments on the APT-C-60 campaign targeting Japan. See you Friday.

About us: This newsletter is written from Japan — a country that has been simultaneously targeted by three nation-states (China, Russia, and North Korea) for over a decade. Two of these three (China and Russia) are UN Security Council permanent members with veto power; one is a nuclear-armed state operating outside the international rules-based order. We are not American. We are not Chinese. We have no geopolitical agenda except one: helping ordinary people and small businesses in non-superpower countries protect themselves from digital warfare they never signed up for.

Written by a Japan-based information security professional with over 20 years of experience, in collaboration with AI assistants.

© 2026 Samurai Cyber Watch. Redistribution with attribution permitted for non-commercial use.