logo

FBI-CISA: Ghost Ransomware Exploits Legacy Cyber Weakness

ID: 3fbf2f0f-026a-565e-bad5-87b9f7514bd9

STIX ID: report--3fbf2f0f-026a-565e-bad5-87b9f7514bd9

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

A joint FBI-CISA advisory warns that the Ghost/Cring ransomware group continues to exploit legacy, unpatched internet-facing vulnerabilities (including Fortinet CVE-2018-13379, Adobe ColdFusion CVEs, Microsoft SharePoint CVE-2019-0604, and ProxyShell Exchange CVEs) to gain access, deploy web shells, and deliver Cobalt Strike and ransomware; the advisory lists TTPs, common open-source escalation and credential theft tools, and IoCs (filenames and MD5 hashes), and emphasizes patching and basic cybersecurity hygiene to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.