Skip to main content
See every side of every news story
Published loading...Updated

Ransomware crims abused Cisco 0-day weeks before disclosure

Interlock exploited the Cisco zero-day vulnerability for over a month before patch release, targeting hospitals, government, and industrial sectors with data theft and extortion tactics.

  • On Wednesday, Amazon Integrated Security reported that Interlock ransomware exploited a zero-day vulnerability in Cisco Secure Firewall Management Center for 36 days before public disclosure on March 4.
  • Amazon Threat Intelligence identified that the group used CVE-2026-20131 to gain root access, confirming "Interlock had a zero-day in their hands, giving them a week's head start to compromise organizations."
  • Moses, chief information security officer of Amazon Integrated Security, wrote that attackers deployed legitimate remote access tools alongside custom malware, creating "multiple redundant remote access mechanisms" for persistence.
  • Cisco updated its security advisory following the findings, while the Cybersecurity and Infrastructure Security Agency added two of the nine recently disclosed vulnerabilities to its catalog of known exploited threats.
  • Five of the nine vulnerabilities Cisco disclosed in its firewalls and SD-WAN systems over the past three weeks have been exploited in the wild, prompting urgent customer upgrades.
Insights by Ground AI

12 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in on Wednesday, March 18, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal