logo

U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalog

ID: abd7a340-d9f0-5d28-b302-0582ad664406

STIX ID: report--abd7a340-d9f0-5d28-b302-0582ad664406

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2025-03-19

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added two high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-24472, an authentication bypass in Fortinet FortiOS/FortiProxy actively exploited to gain super-admin access and linked to SuperBlack ransomware intrusions attributed to the actor 'Mora_001'; and CVE-2025-30066, a supply-chain compromise of the tj-actions/changed-files GitHub Action that was modified to leak CI/CD secrets from affected workflows. Both flaws have confirmed exploitation in the wild, vendor fixes are available, and federal agencies have mandatory remediation deadlines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.