INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

AWS Warns Hackers Exploited Cisco Zero-Day Since January

| 2026-03-19 09:50 CRITICAL HIGH
Executive Summary AI-generated
A prolific ransomware group has been exploiting a zero-day vulnerability in a Cisco firewall product since January, according to a new analysis from AWS. The group's tactics include using CVE-2026-20131 in attacks and deploying custom remote access trojans (RATs) written in JavaScript and Java for persistent control. They also use PowerShell scripts to collect details on victims' networks and install ConnectWise ScreenConnect as a backup entry point, evading antivirus detection by intercepting HTTP requests entirely in memory. The group's real story isn't just about one vulnerability or ransomware group - it's about the fundamental challenge zero-day exploits pose to every security model.
Technical Mitigations AI-generated
* Apply Cisco's security patches: Immediately apply the latest security patches for Cisco Secure Firewall Management Center (FMC) Software to prevent exploitation of CVE-2026-20131. * Monitor logs and detect IoCs: Regularly review logs for indicators of compromise (IoCs), such as suspicious network activity or PowerShell scripts, to detect potential Interlock ransomware operations. * Implement defense in depth measures: Combine layered security controls with regular threat monitoring/hunting and incident response procedures to provide protection against zero-day exploits like CVE-2026-20131. * Conduct security assessments and continuous testing: Regularly conduct security assessments and perform continuous threat hunting to identify potential vulnerabilities, including those that may not be patched yet.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20131CVE-2026-20131
Target & Sectors
NORTH_AMERICA NORTH_AMERICA healthcarehealthcare governmentgovernment healthhealth defensedefense
Incident Timeline
January 26
Threat actors used Interlock to target Amazon Integrated Security since January 26.
organisation Amazon Integrated Security
vulnerability CVE-2026-20131
organisation CJ Moses
March 4
Cisco released software updates to fix the vulnerability on March 4, but hackers had exploited it since January.
organisation Cisco
2026-03-18
Threat actors used CVE-2026-20131 to target Interlock operation since January 26.
vulnerability CVE-2026-20131
organisation CJ Moses
2026-03-19
Interlock deployed a persistent memory-resident backdoor and installed ConnectWise ScreenConnect as a backup entry point.
organisation Kettering Health
organisation Ransomware
organisation CVE-2026
organisation Cisco Secure Firewall Management Center
organisation AWS
organisation Check ScreenConnect
infrastructure Windows
organisation Desktop, Documents
organisation Downloads
organisation RDP
infrastructure Linux
organisation Amazon
organisation The Register
organisation Interlock
organisation Chrome, Edge
organisation WebSocket
organisation TCP
organisation ConnectWise ScreenConnect
organisation Certify
organisation Active Directory Certificate Services
organisation ELF
organisation TOR
data_breach 43 GB
organisation CVSS
organisation Identify HAProxy
organisation Watch for TCP
Tactical Metrics
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​Linux
Affected Product
Metrics
data_breach
43
Gb
Intelligence Sources
Infosecurity-Magazine 2026-03-19