By Phil Muncaster
Publication Date: 2026-03-19 09:50:00
A prolific ransomware group has been exploiting a zero-day vulnerability in a Cisco firewall product since January, according to a new analysis from AWS.
AWS CISO, CJ Moses, warned yesterday that the Interlock operation had been using CVE-2026-20131 in attacks since January 26.
CVE-2026-20131 is a remote code execution (RCE) flaw in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software.
Given a maximum CVSS score of 10, it could “allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device,” according to Cisco.
Read more on Interlock: Interlock Ransomware Targets US Healthcare, IT and Government Sectors.
Thanks to a “misconfigured infrastructure server,” the AWS security team was able to gain rare and full visibility in Interlock’s operational toolkit, Moses said.
Following initial access via zero-day exploitation, the group used a PowerShell script to collect details on victims’…



