Are Fortinet Users at Risk from Mora_001’s SuperBlack Ransomware?

Article Highlights
Off On

The cybersecurity landscape has been rocked by revelations that two vulnerabilities in Fortinet systems, CVE-2024-55591 and CVE-2025-24472, have been exploited by a new menace identified as “Mora_001.” This threat actor has leveraged these weaknesses to deploy SuperBlack ransomware, raising alarms in the tech community. Mora_001’s tactics bear a striking resemblance to those used by the infamous LockBit ransomware group, a connection that has not gone unnoticed by security experts. LockBit, known for its lucrative ransomware attacks, faced significant setbacks in 2024 when international law enforcement efforts led to several arrests and the seizure of devices. Despite these disruptions, the cybercriminal organization remains active, and a developer associated with the group was arrested in Israel for aiding in the creation of ransomware tools.

Critical Vulnerabilities Exploited

The exploitation of the two Fortinet vulnerabilities by Mora_001 highlights the ongoing threats posed by unpatched and vulnerable systems. CVE-2024-55591 and CVE-2025-24472 serve as gateways for the deployment of SuperBlack ransomware, which can cripple an organization’s network infrastructure. Security researchers from Forescout Research–Vedere Labs have underscored the significance of mitigating such threats through a multi-layered defense strategy. Essential steps include patching vulnerable systems, segmenting networks to limit the spread of attacks, and implementing robust security controls that can thwart unauthorized access. In addition, restricting management access, auditing administrator accounts, and reviewing VPN users are crucial measures that fortify the network against such exploits. Notably, the US leads in the number of exposed FortiGate firewalls, followed by India and Brazil, reflecting global exposure to these vulnerabilities.

Vigilance and Robust Cybersecurity Measures Needed

Organizations need to act quickly to counter the threats posed by SuperBlack ransomware and vulnerabilities in Fortinet products. Emphasizing vigilance and strong cybersecurity measures is critical. Security researchers recommend a proactive stance and comprehensive logging to monitor and respond to potential breaches. This defense-in-depth strategy provides multiple security layers, enhancing resilience against advanced cyber threats. The global landscape of ransomware has evolved, with threat actors like Mora_001 and groups like LockBit constantly changing their tactics. Organizations must continuously update and monitor network systems to reduce exploitation risks. Defending against these sophisticated threats requires systems to be up-to-date and fortified. The cybersecurity community must stay alert to persistent dangers, working collectively to protect critical infrastructure and sensitive data from cybercriminal activities. By focusing on these strategies, organizations can better safeguard their assets and maintain robust security postures in the face of evolving cyber threats.

Explore more

How Is OpenAI Building the AI-Native Finance Team?

The traditional image of a bustling corporate finance department overflowing with analysts frantically crunching numbers into spreadsheets has been replaced by a quiet, high-velocity digital nervous system that operates with unprecedented surgical precision. This transformation is currently being led by OpenAI, an organization that is treating artificial intelligence as the foundational architecture of its financial operations rather than a secondary

Can AI Bridge the Gender Gap in Financial Services?

Standing at the precipice of a digital revolution, the financial industry faces a jarring paradox where women populate half the desks but almost none of the corner offices. While women make up nearly half of the financial services workforce, they occupy a staggering 8% of CEO positions in major firms. This disparity is no longer just a social issue; it

Mobile Operators Aim to Avoid 5G Mistakes in 6G Rollout

The global telecommunications landscape is currently vibrating with a cautious intensity as industry leaders reflect on the lessons learned from the previous decade of connectivity hurdles and high-speed promises. While the transition to the fifth generation of mobile networks was meant to usher in an era of instantaneous downloads and automated industrial harmony, many users found the experience to be

Hyperautomation Becomes the New Corporate Nervous System

The modern corporate engine is no longer a collection of gears grinding in isolation but has evolved into a self-correcting organism where every digital impulse triggers a calculated, instantaneous response across the entire organizational architecture. This profound shift marks the era of hyperautomation, a paradigm that transcends the simple mechanical repetition of the past to embrace a holistic, orchestrated ecosystem.

Will LLMs Make Robotic Process Automation Obsolete?

The persistent illusion of total office automation frequently shatters when a single non-standardized PDF document brings a million-dollar robotic process to a grinding halt. Thousands of manual man-hours are still poured into fixing bot errors across global supply chains that were originally marketed as being fully automated. This paradox exists because traditional automation hits a wall when faced with the