Interlock ransomware gang exploited Cisco firewall zero-day weeks before disclosure: Amazon
ID: d264c6d2-ff2c-5eb9-b1ae-a6d0a86d8dbc
STIX ID: report--d264c6d2-ff2c-5eb9-b1ae-a6d0a86d8dbc
Feed Name: The Record from Recorded Future News
Threat Score
Amazon Integrated Security reported that the Interlock ransomware gang exploited a zero-day in Cisco Secure Firewall Management Center (CVE-2026-20131) in January—weeks before public disclosure—using a misconfigured staging server that exposed custom malware, reconnaissance and evasion tools, and their ransom note/negotiation portal; the group has targeted governments, healthcare, and schools, causing significant operational impact and data exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
