FBI-CISA: Ghost Ransomware Exploits Legacy Cyber Weakness
ID: 3fbf2f0f-026a-565e-bad5-87b9f7514bd9
STIX ID: report--3fbf2f0f-026a-565e-bad5-87b9f7514bd9
Feed Name: Cyble Blog
A joint FBI-CISA advisory warns that the Ghost/Cring ransomware group continues to exploit legacy, unpatched internet-facing vulnerabilities (including Fortinet CVE-2018-13379, Adobe ColdFusion CVEs, Microsoft SharePoint CVE-2019-0604, and ProxyShell Exchange CVEs) to gain access, deploy web shells, and deliver Cobalt Strike and ransomware; the advisory lists TTPs, common open-source escalation and credential theft tools, and IoCs (filenames and MD5 hashes), and emphasizes patching and basic cybersecurity hygiene to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
