A critical flaw in Cisco firewall management software was exploited by Interlock ransomware hackers for weeks, targeting critical infrastructure sectors in North America and Europe. The vulnerability, which had a maximum severity score, was leveraged to compromise Cisco firewalls, allowing the attackers to gain unauthorized access to sensitive systems. Researchers from AWS discovered an Interlock server loaded with various tools, highlighting the group's extensive focus on critical infrastructure. The exploitation occurred before Cisco publicly disclosed the vulnerability in early March, putting numerous organizations at risk. The use of this exploit by Interlock ransomware underscores the importance of proactive operational resilience planning, particularly in sectors that are frequently targeted by such groups1. This incident matters to security practitioners because it demonstrates the need for swift patching and robust security measures to mitigate the risk of ransomware attacks on critical infrastructure.
Interlock Ransomware Exploited Cisco Firewall Flaw for Weeks
⚠️ Critical Alert
Why This Matters
Ransomware targeting Cisco highlights sector-specific risk — operational resilience planning is the real takeaway.
References
- Bank Info Security. (2026, March 18). Interlock Ransomware Exploited Cisco Firewall Flaw for Weeks. Bank Info Security. https://www.bankinfosecurity.com/interlock-ransomware-exploited-cisco-firewall-flaw-for-weeks-a-31073
Original Source
Bank Info Security
Read original →