Interlock Exploits Cisco FMC Zero-Day Amid 31 High-Impact March Vulnerabilities
ID: 446c1203-30d0-51d5-9d54-f98ae2ace2f9
STIX ID: report--446c1203-30d0-51d5-9d54-f98ae2ace2f9
Feed Name: Cyber Press
Insikt Group identified 31 actively exploited, high-impact vulnerabilities in March 2026 (29 rated Very Critical), with public PoCs for several flaws; Microsoft and Apple products were heavily targeted and legacy flaws remain in active use. The report highlights exploitation of Cisco Secure FMC (CVE-2026-20131) by the Interlock ransomware group to achieve unauthenticated root Java execution and deploy ELF binaries, RATs, and memory-resident web shells, and recommends prioritizing patching based on active exploitation and observed attacker behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
