Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access
ID: 6a915e71-b037-5ac6-9738-db11a28ef2e2
STIX ID: report--6a915e71-b037-5ac6-9738-db11a28ef2e2
Feed Name: The Hacker News
Amazon Threat Intelligence reports an active Interlock ransomware campaign exploiting CVE-2026-20131 (CVSS 10.0), an insecure deserialization RCE in Cisco Secure FMC used as a zero-day since Jan 26, 2026. Analysis of exposed attacker infrastructure revealed a multi-stage chain that executes arbitrary Java code as root, confirms exploitation via HTTP callbacks, and fetches ELF payloads delivering reconnaissance scripts, Java/JavaScript RATs, memory-resident web shells, reverse-proxy laundering, network beacons, and ScreenConnect for persistence; organizations are urged to patch immediately, assess for compromise, and review defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
