Amazon security boss says crims abused max-security Cisco firewall flaw weeks before disclosure

2026-03-18T19:24:00Z0c48de9668b7abc75784956442dbfc09d1955cee9aa69133b3cbf51faef91c45
AI-enabled crimeCISACVE-2026-20131Chrome zero-dayCisco Secure FirewallInterlockIran-linked operationsStorm-2561credential theftn8nproxy takedownransomwarezero-day

What happened

Collection of security headlines highlighting active exploitation of a maximum-severity Cisco Secure Firewall Management Center vulnerability (CVE-2026-20131) as a zero-day by ransomware actors prior to Cisco’s patch, with the disclosure also exposing the Interlock post-exploit toolkit. Feed also covers broad, high-impact trends: state-linked activity (Iran), growing AI-enabled cybercrime and agent risks, active exploitation of n8n RCE (CISA warning), Chrome zero-days, credential-stealing campaigns spoofing VPN clients (Storm-2561), and law-enforcement disruption of criminal proxy services (S​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
0c48de9668b7abc75784956442dbfc09d1955cee9aa69133b3cbf51faef91c45
Enrichment time
2026-03-18T19:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.