logo

Ransomware gang exploits Cisco flaw in zero-day attacks since January

ID: 8f700b81-b13d-5545-92c5-964b4399aed1

STIX ID: report--8f700b81-b13d-5545-92c5-964b4399aed1

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-03-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

The Interlock ransomware operation exploited a maximum-severity RCE zero-day (CVE-2026-20131) in Cisco Secure Firewall Management Center beginning January 26, 2026—36 days before public disclosure—and used it to compromise enterprise firewalls; Cisco issued a patch on March 4, 2026. Interlock has ties to prior RAT and ransomware activity (NodeSnake, Slopoly) and has claimed or been linked to attacks against healthcare, universities, and municipal targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.