
Amazon Threat Intelligence is alerting users to an ongoing Interlock ransomware attack that’s exploiting a newly discovered critical vulnerability in Cisco Secure Firewall Management Center (FMC) Software.
The vulnerability, identified as CVE-2026-20131 (with a CVSS score of 10.0), involves the insecure deserialization of a Java byte stream provided by the user. This allows a remote, unauthenticated attacker to bypass authentication and execute arbitrary Java code as root on a vulnerable device.
Data from the tech giant’s MadPot global sensor network suggests the vulnerability was exploited as a zero-day from January 26, 2026, over a month before Cisco’s public announcement.
“This was more than just a regular vulnerability exploitation; Interlock had a zero-day exploit, giving them a week’s advantage in compromising organizations before defenses were even aware. Upon discovery, we reported the findings to Cisco, aiding their investigation and the protection of their customers,” stated CJ Moses, CISO of Amazon Integrated Security, in a report shared with The Hacker News.
Amazon explained that the discovery was facilitated by a mistake made by the attacker, which exposed their cybercrime group’s tools via a misconfigured infrastructure server. This exposure revealed their multi-stage attack process, custom remote access trojans, reconnaissance scripts, and circumvention strategies.
The attack sequence involves sending crafted HTTP requests to a specific path within the vulnerable software to execute arbitrary Java code. The compromised system then sends an HTTP PUT request to an external server to confirm successful exploitation. Upon confirmation, commands are issued to retrieve an ELF binary from a remote server hosting other Interlock-related tools.
The identified tools include:
The connection to Interlock is based on related technical and operational indicators, including the ransom note and TOR negotiation portal. Evidence suggests that the threat actor likely operates within the UTC+3 time zone.
Given the active exploitation of this vulnerability, it’s recommended that users promptly apply patches, perform security checks for potential compromises, audit ScreenConnect deployments for unauthorized installations, and enforce defense-in-depth security measures.
“This is not only an exploit campaign by a single ransomware group but the fundamental challenge that zero-day vulnerabilities pose to entire security models,” says Moses. “Even the most up-to-date patching cadence is unable to protect against as yet unknown exploits.”
“Defense in depth is therefore extremely important, and security controls that are layered provide protection when single controls fail. Rapid patching is essential in vulnerability management to avoid the critical exploitation window.
This announcement comes as Google revealed that ransomware groups are adapting their strategies due to decreased payment success, by targeting vulnerabilities in common VPNs and firewalls for initial access. Also, actors are relying more on native Windows capabilities and less on external tools.
Malvertising and SEO tactics have been observed as mechanisms for distributing malware payloads for initial access. Other techniques include using compromised credentials, creating backdoors, deploying remote access software, and using native tools for reconnaissance.
“Although we expect ransomware to stay a primary threat globally, reduced profitability may compel some actors to explore other means of generating revenue,” Google stated. “Such methods could include increased data theft extortion attempts, the employment of more aggressive extortion tactics, or, opportunistically, the use of access to victim environments for secondary monetization mechanisms such as using compromised infrastructure to send phishing messages.”
#(fmc) #access #cisco #cve-2026-20131 #flaw #gain #interlock #news #ransomware #root #uses — News
© Bulletproof Servers. All rights reserved.