
The Interlock ransomware group has been leveraging a critical remote code execution (RCE) vulnerability in Cisco’s Secure Firewall Management Center (FMC) software in zero-day attacks since late January.
The Interlock ransomware gang appeared around September 2024 and has been connected to ClickFix and to malware campaigns where they deployed NodeSnake, a remote access trojan, on U.K. university networks.
Interlock has also taken credit for attacks on DaVita, Kettering Health, the Texas Tech University System, and the city of Saint Paul, Minnesota. Recently, IBM X-Force researchers reported that Interlock is using Slopoly, a new malware, potentially created with AI.
Cisco released a patch for the vulnerability (CVE-2026-20131) on March 4, cautioning that it could allow unauthorized attackers to remotely run arbitrary Java code as root on vulnerable devices.
Amazon’s threat intelligence unit reported on Wednesday that Interlock had been exploiting the Secure FMC vulnerability in attacks against enterprise firewalls for over a month before it was patched.
“Our investigation revealed that Interlock exploited this vulnerability for 36 days before its public disclosure, starting January 26, 2026,” stated CJ Moses, Amazon Integrated Security’s CISO.
“This wasn’t just another exploit; Interlock had a zero-day, giving them a week’s advantage to compromise organizations before defenses were aware.”
“On March 4, 2026, Cisco published a security advisory detailing a vulnerability in Cisco Secure Firewall Management Center Software’s web interface,” Cisco shared with BleepingComputer in an email on Wednesday after its public announcement. “We appreciate Amazon’s partnership and have updated our advisory with the latest details. We strongly recommend customers upgrade immediately and consult our security advisory for further information and guidance.”
This year, Cisco has addressed multiple zero-day vulnerabilities exploited in the wild. For example, in January, they resolved a critical Cisco AsyncOS zero-day used to compromise secure email appliances since November and patched a critical Unified Communications RCE also exploited in zero-day attacks.
Last month, Cisco patched another critical vulnerability that allowed bypass of Catalyst SD-WAN authentication, enabling attackers to compromise controllers and add malicious peers to targeted networks, since 2023.
Update March 18, 12:55 EDT: Cisco statement added.
#attackers. #cisco #exploited #flaw #january #news #ransomware #since #zero-day — News
© Bulletproof Servers. All rights reserved.