Skip to main content

New SuperBlack ransomware exploits Fortinet auth bypass flaws


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

March 13, 2025 By Bill Toulas

 

Ransomware

A new ransomware operator named 'Mora_001' is exploiting two Fortinet vulnerabilities to gain unauthorized access to firewall appliances and deploy a custom ransomware strain dubbed SuperBlack.

The two vulnerabilities, both authentication bypasses, are CVE-2024-55591 and CVE-2025-24472, which Fortinet disclosed in January and February, respectively.

When Fortinet first disclosed CVE-2024-55591 on January 14, they confirmed it had been exploited as a zero-day, with Arctic Wolf stating it had been used in attacks since November 2024 to breach FortiGate firewalls.

Confusingly, on February 11, Fortinet added CVE-2025-2447 to their January advisory, which led many to believe it was a newly exploited flaw. However, Fortinet told BleepingComputer that this bug was also fixed in January 2024 and was not exploited.

"We are not aware of CVE-2025-24472 ever being exploited," Fortinet told BleepingComputer at the time.

However, a new report by Forescout researchers, says they discovered the SuperBlack attacks in late January 2025, with the threat actor utilizing CVE-2025-24472 as early as February 2, 2025.

 

>>Full Article<<

0 replies

Be the first to reply!

Reply