Amazon security boss says crims abused max-security Cisco firewall flaw weeks before disclosure
ID: 3f1bfaee-0a06-53d7-9061-891db2c3cce8
STIX ID: report--3f1bfaee-0a06-53d7-9061-891db2c3cce8
Feed Name: The Register (Security)
Amazon reported that the Interlock ransomware group exploited a critical zero-day in Cisco Secure Firewall Management Center (CVE-2026-20131) at least 36 days before Cisco released fixes; Interlock's operations include extensive post-exploit tooling — PowerShell exfiltration scripts, Java/JavaScript implants, Linux persistence and memory-resident backdoors — and have impacted healthcare providers and a municipal victim, resulting in data theft, service disruption, and public data leaks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
