AWS Warns Hackers Have Abused Cisco Firewall Zero-Day Since January
ID: ebba9c65-6ac6-55cb-9415-316d566e475a
STIX ID: report--ebba9c65-6ac6-55cb-9415-316d566e475a
Feed Name: Infosecurity Magazine (News)
AWS reports that the Interlock ransomware group has been actively exploiting a zero-day RCE (CVE-2026-20131) in Cisco Secure Firewall Management Center since January 26, enabling unauthenticated arbitrary Java code execution as root. AWS observed attackers performing network reconnaissance via PowerShell, deploying custom JavaScript and Java RATs, using an in-memory webshell to evade detection, and installing ConnectWise ScreenConnect for backup access; organizations are advised to apply Cisco patches, review IoCs, and hunt for the described TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
