Interlock ransomware gang exploited Cisco firewall zero-day weeks before disclosure: Amazon
2026-03-19T14:51:55Z•f1a47bd941ff63f20ee374d2d9ecb37f7cd1be3ad017756c2a55020595dd0352
APT28CISACisco firewallDarkSwordInterlockRussiaUkraineZimbracritical-vulnerabilitycyberespionageelection-securityiPhone exploitmobile exploitransomwarezero-day
What happened
Multiple high-impact incidents: the Interlock ransomware gang exploited a zero‑day in a popular Cisco firewall line weeks before public disclosure (Amazon report); Russian state‑linked actors (APT28) exploited a Zimbra webmail vulnerability to breach a Ukrainian maritime agency; and a Russia‑linked campaign using an advanced iPhone exploit called “DarkSword” can compromise iPhones with little or no user interaction, exfiltrate data rapidly, and remove traces (Lookout). Related reporting highlights US concerns about CISA staffing and broader election‑security assessments. No public CVE IDs were
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- f1a47bd941ff63f20ee374d2d9ecb37f7cd1be3ad017756c2a55020595dd0352
- Enrichment time
- 2026-03-19T14:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.