Patch Now: Ransomware Operators Exploiting Two Fortinet Vulnerabilities
ID: 1e174137-df15-503f-b7b8-85eb6333ccb7
STIX ID: report--1e174137-df15-503f-b7b8-85eb6333ccb7
Feed Name: Halcyon Blog
Researchers have observed a new ransomware group, Mora_001, actively exploiting two FortiGate vulnerabilities (CVE-2024-55591 and CVE-2025-24472) since late January to deploy a SuperBlack ransomware strain that resembles LockBit 3.0 but includes a customized ransom note and a unique data-exfiltration tool; despite Fortinet patches, many systems remain unpatched, and the report highlights broader trends of rapid zero-day exploitation, AI-driven automation, and increased attack surface targeting firewall management interfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
