Cybersecurity — 2026-03-26

Interlock Ransomware Exploits Cisco FMC Zero-Day for Unauthenticated Root Access Since January

The Interlock ransomware group is actively exploiting CVE-2026-20131, a CVSS 10.0 insecure deserialization flaw in Cisco Firepower Management Center's web management interface, to achieve unauthenticated remote code execution as root. Amazon threat intelligence, using its MadPot honeypot network, identified exploitation in the wild since January 26—36 days before Cisco's March 4 disclosure. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on March 19. A misconfigured attacker server exposed Interlock's full operational toolkit including custom RATs and evasion tools. Separately, SentinelOne reports threat actors are exploiting FortiGate Next-Generation Firewall appliances (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) to extract configuration files containing encrypted LDAP credentials, decrypt them, and authenticate to Active Directory—activity consistent with an initial access broker targeting healthcare, government, and managed service providers.

2 sources
  1. FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials - The Hacker News
  2. Amazon threat intelligence teams identify Interlock ransomware campaign targeting enterprise firewalls - AWS Security Blog

View in full brief →

UNCLASSIFIED // OPEN SOURCE