Ransomware gang exploits Cisco flaw in zero-day attacks since January
ID: 8f700b81-b13d-5545-92c5-964b4399aed1
STIX ID: report--8f700b81-b13d-5545-92c5-964b4399aed1
Feed Name: Bleeping Computer
Threat Score
The Interlock ransomware operation exploited a maximum-severity RCE zero-day (CVE-2026-20131) in Cisco Secure Firewall Management Center beginning January 26, 2026—36 days before public disclosure—and used it to compromise enterprise firewalls; Cisco issued a patch on March 4, 2026. Interlock has ties to prior RAT and ransomware activity (NodeSnake, Slopoly) and has claimed or been linked to attacks against healthcare, universities, and municipal targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
