logo

Interlock Ransomware Leveraged Cisco FMC Zero-Day 36 Days Before Patch

ID: a2cfda7d-f559-587a-a0a2-93db99f75d8d

STIX ID: report--a2cfda7d-f559-587a-a0a2-93db99f75d8d

Feed Name: The Cyber Express

Threat Score
88/100

Date Published: 2026-03-19

Date Updated: 2026-05-05

Author: Ashish Khaitan

...
...

Amazon’s threat intelligence observed Interlock exploiting a zero-day in Cisco Secure Firewall Management Center (CVE-2026-20131) to achieve root Java code execution, perform multi-stage post-exploitation (RATs, fileless webshells, reverse proxies), and prepare ransomware operations; Amazon MadPot honeypots captured exploitation prior to public disclosure and exposed the attackers’ organized toolkit and targeting across education, engineering, manufacturing, healthcare, and public sector organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.