Critical Fortinet Vulnerability Draws Fresh Attention
ID: ee2090a1-2b4b-554e-9e74-4688b3b40422
STIX ID: report--ee2090a1-2b4b-554e-9e74-4688b3b40422
Feed Name: Dark Reading
Fortinet disclosed two critical authentication-bypass vulnerabilities (CVE-2025-24472 and CVE-2024-55591) that allow unauthenticated attackers to achieve super-admin access on FortiOS and FortiProxy devices; CISA added at least one to its Known Exploited Vulnerabilities catalog. Security vendors report active exploitation in the wild, with a ransomware operator tracked as Mora_001 leveraging the flaws for initial access, privilege escalation, persistence (creating admin accounts, scheduled scripts, syncing backups), lateral movement, data exfiltration, and deployment of a ransomware variant called "SuperBlack"—prompting urgent patching and mitigation for exposed management interfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
