logo

Patch Now: Ransomware Operators Exploiting Two Fortinet Vulnerabilities

ID: 1e174137-df15-503f-b7b8-85eb6333ccb7

STIX ID: report--1e174137-df15-503f-b7b8-85eb6333ccb7

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-03-17

Date Updated: 2026-04-28

...
...

Researchers have observed a new ransomware group, Mora_001, actively exploiting two FortiGate vulnerabilities (CVE-2024-55591 and CVE-2025-24472) since late January to deploy a SuperBlack ransomware strain that resembles LockBit 3.0 but includes a customized ransom note and a unique data-exfiltration tool; despite Fortinet patches, many systems remain unpatched, and the report highlights broader trends of rapid zero-day exploitation, AI-driven automation, and increased attack surface targeting firewall management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.