<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>authentication bypass vulnerability &#8211; pk-360</title>
	<atom:link href="https://pk-360.com/tag/authentication-bypass-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>https://pk-360.com</link>
	<description>IT Solutions, Support, Insight, Ideas, and Business Solutions</description>
	<lastBuildDate>Tue, 02 Sep 2025 07:01:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://pk-360.com/wp-content/uploads/2025/08/pk-360-150x150.png</url>
	<title>authentication bypass vulnerability &#8211; pk-360</title>
	<link>https://pk-360.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>New Cybersecurity Warning: Ransomware Actors Tied to LockBit</title>
		<link>https://pk-360.com/new-cybersecurity-warning-ransomware-actors-tied-to-lockbit/</link>
					<comments>https://pk-360.com/new-cybersecurity-warning-ransomware-actors-tied-to-lockbit/#comments</comments>
		
		<dc:creator><![CDATA[Haider]]></dc:creator>
		<pubDate>Tue, 26 Aug 2025 10:45:04 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[authentication bypass vulnerability]]></category>
		<category><![CDATA[best every blogs]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blog on cyber security]]></category>
		<category><![CDATA[blog on cybersecurity]]></category>
		<category><![CDATA[blog on health]]></category>
		<category><![CDATA[blog on latest updates]]></category>
		<category><![CDATA[blog on movies]]></category>
		<category><![CDATA[blog on tech]]></category>
		<category><![CDATA[blogs]]></category>
		<category><![CDATA[blogs on health]]></category>
		<category><![CDATA[blogs on life style]]></category>
		<category><![CDATA[blogs on movies]]></category>
		<category><![CDATA[blogs on tech]]></category>
		<category><![CDATA[computer security news]]></category>
		<category><![CDATA[cubersecurity]]></category>
		<category><![CDATA[CVE-2024-55591]]></category>
		<category><![CDATA[CVE-2025-24472]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber defense]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security blog]]></category>
		<category><![CDATA[cyber security what is]]></category>
		<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[cyber-security news]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cybersecurity blog]]></category>
		<category><![CDATA[cybersecurity blogs]]></category>
		<category><![CDATA[cybersecurity news]]></category>
		<category><![CDATA[cybersecurity threats 2025]]></category>
		<category><![CDATA[data breach prevention]]></category>
		<category><![CDATA[double extortion ransomware]]></category>
		<category><![CDATA[FortiGate firewall]]></category>
		<category><![CDATA[Fortinet security patch]]></category>
		<category><![CDATA[Fortinet vulnerabilities]]></category>
		<category><![CDATA[FortiOS exploit]]></category>
		<category><![CDATA[FortiProxy exploit]]></category>
		<category><![CDATA[health blog]]></category>
		<category><![CDATA[health blogs]]></category>
		<category><![CDATA[life styel blog]]></category>
		<category><![CDATA[life style blogs]]></category>
		<category><![CDATA[LockBit]]></category>
		<category><![CDATA[Mora_001]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[news cybersecurity]]></category>
		<category><![CDATA[PK-360]]></category>
		<category><![CDATA[pk360]]></category>
		<category><![CDATA[ransomware advisory]]></category>
		<category><![CDATA[ransomware protection]]></category>
		<category><![CDATA[SuperBlack ransomware]]></category>
		<category><![CDATA[tech blog]]></category>
		<category><![CDATA[tech blogs]]></category>
		<category><![CDATA[threat actors]]></category>
		<category><![CDATA[top quality blogs]]></category>
		<category><![CDATA[what is cyber security]]></category>
		<category><![CDATA[what is cybersecurity]]></category>
		<guid isPermaLink="false">https://pk-360.com/?p=999</guid>

					<description><![CDATA[This article is about New Cybersecurity Warning: Ransomware Actors Tied to Lock Bit Mora_001, a ransomware group linked to LockBit, is the subject of an upcoming discussion. The group has been actively exploiting major vulnerabilities in Fortinet’s FortiOS and FortiProxy products. These security flaws have allowed attackers to gain unauthorized access to systems, leading to]]></description>
										<content:encoded><![CDATA[<p></p>
<h2 class="wp-block-heading">This article is about New Cybersecurity Warning: Ransomware Actors Tied to Lock Bit</h2>
<p></p>
<p class="wp-block-paragraph">Mora_001, a ransomware group linked to LockBit, is the subject of an upcoming discussion. The group has been actively exploiting major vulnerabilities in <strong>Fortinet’s FortiOS</strong> and <strong>FortiProxy</strong> products. These security flaws have allowed attackers to gain unauthorized access to systems, leading to the deployment of a new type of ransomware called <strong>SuperBlack</strong>. <a href="https://pk-360.com/2025/08/06/top-5-it-solutions/" data-type="post" data-id="393">Organizations</a> with exposed FortiGate firewalls have been the targets of these attacks since late January 2025. In response, Fortinet has released patches and is urging users to update their systems immediately</p>
<p></p>
<h1 class="wp-block-heading">Technical Details</h1>
<p></p>
<h2 class="wp-block-heading">Vulnerabilities Involved</h2>
<p></p>
<h3 class="wp-block-heading">(1)&nbsp; &nbsp; &nbsp; &nbsp; CVE-2024-55591.&nbsp; &nbsp; &nbsp;</h3>
<p></p>
<p class="wp-block-paragraph">Fortinet has identified a <a href="https://pk-360.com/category/cyber-security/information-security/" data-type="category" data-id="25">critical authentication</a> bypass vulnerability in its <strong>FortiOS</strong> (versions 7.0.0-7.0.16) and <strong>FortiProxy</strong> (versions 7.0.0-7.0.19 and 7.2.0-7.2.12) products. This flaw allows a remote attacker to achieve <strong>super-admin</strong> access by exploiting a weakness in the Node.js WebSocket module. The vulnerability can lead to unauthorized code or command execution</p>
<p></p>
<h3 class="wp-block-heading">(2)&nbsp; &nbsp; &nbsp; &nbsp; CVE-2025-24472. &nbsp; &nbsp;</h3>
<p></p>
<p class="wp-block-paragraph">A related high-severity authentication bypass vulnerability, impacting the same product versions, was identified through victim reports during Forescout’s investigations. This issue is fixed by the same patch that also addresses CVE-2024-55591 &nbsp;</p>
<p></p>
<h1 class="wp-block-heading">Attack Methodology</h1>
<p></p>
<ul class="wp-block-list">
<li style="list-style-type: none;">
<ul></ul>
</li>
</ul>
<h5><ul><li>Attackers exploited the mentioned vulnerabilities to get <strong style="letter-spacing: 0px;">unauthorized access</strong> with <strong style="letter-spacing: 0px;">super-admin privileges</strong>.</li><li>Attackers created new privileged accounts, using names like <strong style="letter-spacing: 0px;">forticloud-tech</strong>, <strong style="letter-spacing: 0px;">fortigate-firewall</strong>, and <strong style="letter-spacing: 0px;">administrator</strong>.</li><li>For firewalls with VPN capabilities, the attackers created local user accounts that mimicked legitimate users. This was done to maintain <strong style="letter-spacing: 0px;">persistent access</strong> to the compromised systems.</li><li>In their attacks, the threat actors used the <strong style="letter-spacing: 0px;">high availability (HA)</strong> configuration of the firewalls to their advantage. By compromising one device, they could <strong style="letter-spacing: 0px;">automatically spread</strong> their access to other firewalls within the same cluster. This tactic allowed them to <strong style="letter-spacing: 0px;">compromise additional devices</strong> without needing to attack them individually.&nbsp;</li><li>The group&#8217;s final step was to <strong style="letter-spacing: 0px;">deploy</strong> the <strong style="letter-spacing: 0px;">SuperBlack</strong> ransomware. This variant, based on the LockBit 3.0 builder, is designed for <strong style="letter-spacing: 0px;">double extortion</strong> by first <strong style="letter-spacing: 0px;">stealing data</strong> and then encrypting files. It also includes a <strong style="letter-spacing: 0px;">custom wiper tool</strong> to <strong style="letter-spacing: 0px;">erase</strong> traces of the ransomware executable, making it harder to investigate.</li></ul></h5>
<p></p>
<p></p>
<p></p>
<p></p>
<p></p>
<p></p>
<h1 class="wp-block-heading">Recommendations</h1>
<p></p>
<h3 class="wp-block-heading">All Fortinet administrators/users are urged to update their products as mentioned below:</h3>
<p></p>
<h3 class="wp-block-heading">a. &nbsp; &nbsp; &nbsp; &nbsp; Upgrade FortiOS to version 7.0.17 or later.</h3>
<p></p>
<h3 class="wp-block-heading">b. &nbsp; &nbsp; &nbsp; &nbsp; Upgrade FortiProxy to version 7.2.13 or later or 7.0.20.</h3>
<p></p>
<h3 class="wp-block-heading">c. &nbsp; &nbsp; &nbsp; &nbsp; Remove the firewall’s web-based management interface from public internet exposure.</h3>
<p></p>
<h3 class="wp-block-heading">d. &nbsp; &nbsp; &nbsp; &nbsp; Regularly review administrative accounts for unauthorized additions or changes.</h3>
<p></p>
<h3 class="wp-block-heading">e. &nbsp; &nbsp; &nbsp; &nbsp; Monitor for unexpected configuration changes and unauthorized login attempts.</h3>
<p></p>
<h3 class="wp-block-heading">f.&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Be vigilant for indicators of compromise, such as unusual automation tasks or unexpected VPN connections.</h3>
<p></p>
<h3 class="wp-block-heading">g. &nbsp; &nbsp; &nbsp; &nbsp; Implement strict network segmentation to limit lateral movement opportunities for attackers.</h3>
<p></p>
<h3 class="wp-block-heading">h. &nbsp; &nbsp; &nbsp; &nbsp; Enforce multi-factor authentication (MFA) for all administrative access.</h3>
<p></p>
<h1 class="wp-block-heading">Conclusion</h1>
<p></p>
<p class="wp-block-paragraph">The recent activities of Mora_001 highlight the growing sophistication of ransomware actors tied to LockBit, particularly their ability to exploit critical vulnerabilities in widely used security products. The deployment of SuperBlack ransomware demonstrates the severe risks organizations face when systems remain unpatched or exposed. Timely updates, strict access controls, and proactive monitoring are essential to defend against these evolving threats. Organizations should treat this advisory with urgency, as the combination of double extortion and stealthy persistence techniques makes this campaign especially dangerous. Staying vigilant and applying Fortinet’s recommended patches is the most effective defense against these attacks</p>
<p></p>
<p class="wp-block-paragraph"></p>]]></content:encoded>
					
					<wfw:commentRss>https://pk-360.com/new-cybersecurity-warning-ransomware-actors-tied-to-lockbit/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
