Cybersecurity & Privacy — 2026-03-23

Interlock Ransomware Group Exploits Cisco Firepower Management Center Zero-Day for Root Access

The Interlock ransomware group is actively exploiting a zero-day vulnerability (CVE-2026-20131) in Cisco's Firepower Management Center to gain root access to enterprise network security appliances. The attack chain enables full control of the firewall management infrastructure, providing attackers with visibility into network traffic and the ability to disable security controls before deploying ransomware. Exploitation of a critical network security management platform represents an escalation in ransomware operator sophistication.

1 sources
  1. Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE