Cybersecurity & Privacy — 2026-03-23
Interlock Ransomware Group Exploits Cisco Firepower Management Center Zero-Day for Root Access
The Interlock ransomware group is actively exploiting a zero-day vulnerability (CVE-2026-20131) in Cisco's Firepower Management Center to gain root access to enterprise network security appliances. The attack chain enables full control of the firewall management infrastructure, providing attackers with visibility into network traffic and the ability to disable security controls before deploying ransomware. Exploitation of a critical network security management platform represents an escalation in ransomware operator sophistication.