Cisco Firewall Zero-Day Actively Exploited to Deliver Interlock Ransomware
ID: 3cb07b12-a4f2-52e3-9b84-49753d23a246
STIX ID: report--3cb07b12-a4f2-52e3-9b84-49753d23a246
Feed Name: GBHackers
Security researchers uncovered an active Interlock ransomware campaign exploiting CVE-2026-20131, a critical unauthenticated Java deserialization RCE (CWE-502, CVSS 10.0) in Cisco Secure Firewall Management Center that allowed remote code execution and root access; operators exploited the flaw for 36 days before disclosure, deploying PowerShell reconnaissance, custom Java/JavaScript remote access trojans, memory-resident webshells, and exfiltration of host-specific archives while targeting education, manufacturing, healthcare, and engineering sectors—organizations must apply official patches immediately and hunt for memory-resident anomalies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
