Interlock ransomware gang exploited Cisco firewall zero-day weeks before disclosure: Amazon

2026-03-19T14:51:55Zf1a47bd941ff63f20ee374d2d9ecb37f7cd1be3ad017756c2a55020595dd0352
APT28CISACisco firewallDarkSwordInterlockRussiaUkraineZimbracritical-vulnerabilitycyberespionageelection-securityiPhone exploitmobile exploitransomwarezero-day

What happened

Multiple high-impact incidents: the Interlock ransomware gang exploited a zero‑day in a popular Cisco firewall line weeks before public disclosure (Amazon report); Russian state‑linked actors (APT28) exploited a Zimbra webmail vulnerability to breach a Ukrainian maritime agency; and a Russia‑linked campaign using an advanced iPhone exploit called “DarkSword” can compromise iPhones with little or no user interaction, exfiltrate data rapidly, and remove traces (Lookout). Related reporting highlights US concerns about CISA staffing and broader election‑security assessments. No public CVE IDs were

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
f1a47bd941ff63f20ee374d2d9ecb37f7cd1be3ad017756c2a55020595dd0352
Enrichment time
2026-03-19T14:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.