Interlock Ransomware Leveraged Cisco FMC Zero-Day 36 Days Before Patch
ID: a2cfda7d-f559-587a-a0a2-93db99f75d8d
STIX ID: report--a2cfda7d-f559-587a-a0a2-93db99f75d8d
Feed Name: The Cyber Express
Amazon’s threat intelligence observed Interlock exploiting a zero-day in Cisco Secure Firewall Management Center (CVE-2026-20131) to achieve root Java code execution, perform multi-stage post-exploitation (RATs, fileless webshells, reverse proxies), and prepare ransomware operations; Amazon MadPot honeypots captured exploitation prior to public disclosure and exposed the attackers’ organized toolkit and targeting across education, engineering, manufacturing, healthcare, and public sector organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
