<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ransomware-crims-abused-cisco-0-day-weeks-before-disclosure-igf7rganp" -->

---
title: Ransomware crims abused Cisco 0-day weeks before disclosure
description: The Interlock ransomware group exploited CVE-2026-20131, a maximum-severity remote code execution flaw in Cisco Secure Firewall Management Center, as a...
canonical: https://daily.dev/posts/ransomware-crims-abused-cisco-0-day-weeks-before-disclosure-igf7rganp
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Ransomware crims abused Cisco 0-day weeks before disclosure | daily.dev
og:description: The Interlock ransomware group exploited CVE-2026-20131, a maximum-severity remote code execution flaw in Cisco Secure Firewall Management Center, as a...
og:url: https://daily.dev/posts/ransomware-crims-abused-cisco-0-day-weeks-before-disclosure-igf7rganp
og:image: https://api.daily.dev/og/posts/iGF7RgaNp.png
og:image:alt: Ransomware crims abused Cisco 0-day weeks before disclosure
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Ransomware crims abused Cisco 0-day weeks before disclosure

**[The Register](https://daily.dev/sources/theregister)** · 5 min read · 0 upvotes · 0 comments

## Summary

The Interlock ransomware group exploited CVE-2026-20131, a maximum-severity remote code execution flaw in Cisco Secure Firewall Management Center, as a zero-day for 36 days before Cisco patched it on March 4. Amazon's CISO CJ Moses disclosed the findings, noting that Amazon's MadPot honeypot network caught the exploit traffic and also discovered a misconfigured Interlock infrastructure server that exposed their full post-exploitation toolkit. That toolkit includes PowerShell reconnaissance scripts, a JavaScript browser implant using WebSocket C2 communications, a Java-based GlassFish implant as a backup, a Linux reverse proxy Bash script, memory-resident backdoors that avoid disk writes, and legitimate tools like ConnectWise ScreenConnect, Volatility, and Certify to blend in with normal traffic. Interlock has previously targeted hospitals, medical facilities, and municipal governments.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://go.theregister.com/feed/www.theregister.com/2026/03/18/amazon_cisco_firewall_0_day_ransomware/>

---

Tags: [#aws](https://daily.dev/tags/aws), [#malware](https://daily.dev/tags/malware), [#ransomware](https://daily.dev/tags/ransomware), [#cisco](https://daily.dev/tags/cisco), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/ransomware-crims-abused-cisco-0-day-weeks-before-disclosure-igf7rganp)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Ransomware crims abused Cisco 0-day weeks before disclosure","url":"https://daily.dev/posts/ransomware-crims-abused-cisco-0-day-weeks-before-disclosure-igf7rganp","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ransomware-crims-abused-cisco-0-day-weeks-before-disclosure-igf7rganp"},"datePublished":"2026-03-18T17:42:58.773Z","dateModified":"2026-03-20T13:05:44.403Z","description":"The Interlock ransomware group exploited CVE-2026-20131, a maximum-severity remote code execution flaw in Cisco Secure Firewall Management Center, as a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7671722266558c9fc0efeca8f486513f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7671722266558c9fc0efeca8f486513f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Register","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Register","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/66aa2113fdad463992ffcbf0e8963fda","url":"https://daily.dev/sources/theregister"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ransomware-crims-abused-cisco-0-day-weeks-before-disclosure-igf7rganp","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"aws,malware,ransomware,cisco,zero-day","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Register","item":"https://daily.dev/sources/theregister"},{"@type":"ListItem","position":3,"name":"Ransomware crims abused Cisco 0-day weeks before disclosure"}]}
```

