Cybersecurity & Privacy — 2026-03-20
Interlock Ransomware Exploited Cisco FMC Zero-Day 36 Days Before Disclosure; CISA Sets March 22 Patch Deadline
Amazon's threat intelligence team discovered that Interlock ransomware exploited CVE-2026-20131 (CVSS 10.0) in Cisco Secure Firewall Management Center since January 26, 36 days before Cisco's March 4 disclosure. The deserialization flaw grants unauthenticated remote root access. CISA added the CVE to its KEV catalog March 19 with a March 22 patch deadline for FCEB agencies. Prior Interlock victims include St. Paul, Minnesota (required National Guard response), DaVita, and Kettering Health.
Analysis
The Mar 19 INTSUM covered the Glassworm npm supply chain attack andSection 702 SAFE Act. Interlock's Cisco FMC exploitation adds a second major cyber story this week. Amazon's discovery through a misconfigured staging server suggests Interlock's operational security has degraded, potentially enabling further attribution.
The Mar 19 INTSUM covered the Glassworm npm supply chain attack and