Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware
ID: 27b37c27-af23-5ba7-bbbd-157b55cf224f
STIX ID: report--27b37c27-af23-5ba7-bbbd-157b55cf224f
Feed Name: cybersecurityNews.com
Amazon threat intelligence discovered the Interlock ransomware group exploiting a critical Cisco Secure Firewall Management Center zero-day (CVE-2026-20131) in the wild beginning 26 January 2026—36 days prior to the public disclosure—enabling unauthenticated Java code execution as root. The exposed infrastructure revealed a tailored toolkit for each target including a Linux ELF ransom binary, PowerShell host enumeration and zipping, Java/JavaScript remote access trojans, a memory-resident Java webshell, and Linux reverse-proxy scripts; Interlock targets critical sectors and uses double-extortion tactics, so organizations should apply Cisco patches immediately and prioritize behavioral/memory-based detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
