<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cyber security &#8211; pk-360</title>
	<atom:link href="https://pk-360.com/tag/cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://pk-360.com</link>
	<description>IT Solutions, Support, Insight, Ideas, and Business Solutions</description>
	<lastBuildDate>Thu, 11 Sep 2025 10:10:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://pk-360.com/wp-content/uploads/2025/08/pk-360-150x150.png</url>
	<title>cyber security &#8211; pk-360</title>
	<link>https://pk-360.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>New Cybersecurity Warning: Ransomware Actors Tied to LockBit</title>
		<link>https://pk-360.com/new-cybersecurity-warning-ransomware-actors-tied-to-lockbit/</link>
					<comments>https://pk-360.com/new-cybersecurity-warning-ransomware-actors-tied-to-lockbit/#comments</comments>
		
		<dc:creator><![CDATA[Haider]]></dc:creator>
		<pubDate>Tue, 26 Aug 2025 10:45:04 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[authentication bypass vulnerability]]></category>
		<category><![CDATA[best every blogs]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blog on cyber security]]></category>
		<category><![CDATA[blog on cybersecurity]]></category>
		<category><![CDATA[blog on health]]></category>
		<category><![CDATA[blog on latest updates]]></category>
		<category><![CDATA[blog on movies]]></category>
		<category><![CDATA[blog on tech]]></category>
		<category><![CDATA[blogs]]></category>
		<category><![CDATA[blogs on health]]></category>
		<category><![CDATA[blogs on life style]]></category>
		<category><![CDATA[blogs on movies]]></category>
		<category><![CDATA[blogs on tech]]></category>
		<category><![CDATA[computer security news]]></category>
		<category><![CDATA[cubersecurity]]></category>
		<category><![CDATA[CVE-2024-55591]]></category>
		<category><![CDATA[CVE-2025-24472]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber defense]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security blog]]></category>
		<category><![CDATA[cyber security what is]]></category>
		<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[cyber-security news]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cybersecurity blog]]></category>
		<category><![CDATA[cybersecurity blogs]]></category>
		<category><![CDATA[cybersecurity news]]></category>
		<category><![CDATA[cybersecurity threats 2025]]></category>
		<category><![CDATA[data breach prevention]]></category>
		<category><![CDATA[double extortion ransomware]]></category>
		<category><![CDATA[FortiGate firewall]]></category>
		<category><![CDATA[Fortinet security patch]]></category>
		<category><![CDATA[Fortinet vulnerabilities]]></category>
		<category><![CDATA[FortiOS exploit]]></category>
		<category><![CDATA[FortiProxy exploit]]></category>
		<category><![CDATA[health blog]]></category>
		<category><![CDATA[health blogs]]></category>
		<category><![CDATA[life styel blog]]></category>
		<category><![CDATA[life style blogs]]></category>
		<category><![CDATA[LockBit]]></category>
		<category><![CDATA[Mora_001]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[news cybersecurity]]></category>
		<category><![CDATA[PK-360]]></category>
		<category><![CDATA[pk360]]></category>
		<category><![CDATA[ransomware advisory]]></category>
		<category><![CDATA[ransomware protection]]></category>
		<category><![CDATA[SuperBlack ransomware]]></category>
		<category><![CDATA[tech blog]]></category>
		<category><![CDATA[tech blogs]]></category>
		<category><![CDATA[threat actors]]></category>
		<category><![CDATA[top quality blogs]]></category>
		<category><![CDATA[what is cyber security]]></category>
		<category><![CDATA[what is cybersecurity]]></category>
		<guid isPermaLink="false">https://pk-360.com/?p=999</guid>

					<description><![CDATA[This article is about New Cybersecurity Warning: Ransomware Actors Tied to Lock Bit Mora_001, a ransomware group linked to LockBit, is the subject of an upcoming discussion. The group has been actively exploiting major vulnerabilities in Fortinet’s FortiOS and FortiProxy products. These security flaws have allowed attackers to gain unauthorized access to systems, leading to]]></description>
										<content:encoded><![CDATA[<p></p>
<h2 class="wp-block-heading">This article is about New Cybersecurity Warning: Ransomware Actors Tied to Lock Bit</h2>
<p></p>
<p class="wp-block-paragraph">Mora_001, a ransomware group linked to LockBit, is the subject of an upcoming discussion. The group has been actively exploiting major vulnerabilities in <strong>Fortinet’s FortiOS</strong> and <strong>FortiProxy</strong> products. These security flaws have allowed attackers to gain unauthorized access to systems, leading to the deployment of a new type of ransomware called <strong>SuperBlack</strong>. <a href="https://pk-360.com/2025/08/06/top-5-it-solutions/" data-type="post" data-id="393">Organizations</a> with exposed FortiGate firewalls have been the targets of these attacks since late January 2025. In response, Fortinet has released patches and is urging users to update their systems immediately</p>
<p></p>
<h1 class="wp-block-heading">Technical Details</h1>
<p></p>
<h2 class="wp-block-heading">Vulnerabilities Involved</h2>
<p></p>
<h3 class="wp-block-heading">(1)&nbsp; &nbsp; &nbsp; &nbsp; CVE-2024-55591.&nbsp; &nbsp; &nbsp;</h3>
<p></p>
<p class="wp-block-paragraph">Fortinet has identified a <a href="https://pk-360.com/category/cyber-security/information-security/" data-type="category" data-id="25">critical authentication</a> bypass vulnerability in its <strong>FortiOS</strong> (versions 7.0.0-7.0.16) and <strong>FortiProxy</strong> (versions 7.0.0-7.0.19 and 7.2.0-7.2.12) products. This flaw allows a remote attacker to achieve <strong>super-admin</strong> access by exploiting a weakness in the Node.js WebSocket module. The vulnerability can lead to unauthorized code or command execution</p>
<p></p>
<h3 class="wp-block-heading">(2)&nbsp; &nbsp; &nbsp; &nbsp; CVE-2025-24472. &nbsp; &nbsp;</h3>
<p></p>
<p class="wp-block-paragraph">A related high-severity authentication bypass vulnerability, impacting the same product versions, was identified through victim reports during Forescout’s investigations. This issue is fixed by the same patch that also addresses CVE-2024-55591 &nbsp;</p>
<p></p>
<h1 class="wp-block-heading">Attack Methodology</h1>
<p></p>
<ul class="wp-block-list">
<li style="list-style-type: none;">
<ul></ul>
</li>
</ul>
<h5><ul><li>Attackers exploited the mentioned vulnerabilities to get <strong style="letter-spacing: 0px;">unauthorized access</strong> with <strong style="letter-spacing: 0px;">super-admin privileges</strong>.</li><li>Attackers created new privileged accounts, using names like <strong style="letter-spacing: 0px;">forticloud-tech</strong>, <strong style="letter-spacing: 0px;">fortigate-firewall</strong>, and <strong style="letter-spacing: 0px;">administrator</strong>.</li><li>For firewalls with VPN capabilities, the attackers created local user accounts that mimicked legitimate users. This was done to maintain <strong style="letter-spacing: 0px;">persistent access</strong> to the compromised systems.</li><li>In their attacks, the threat actors used the <strong style="letter-spacing: 0px;">high availability (HA)</strong> configuration of the firewalls to their advantage. By compromising one device, they could <strong style="letter-spacing: 0px;">automatically spread</strong> their access to other firewalls within the same cluster. This tactic allowed them to <strong style="letter-spacing: 0px;">compromise additional devices</strong> without needing to attack them individually.&nbsp;</li><li>The group&#8217;s final step was to <strong style="letter-spacing: 0px;">deploy</strong> the <strong style="letter-spacing: 0px;">SuperBlack</strong> ransomware. This variant, based on the LockBit 3.0 builder, is designed for <strong style="letter-spacing: 0px;">double extortion</strong> by first <strong style="letter-spacing: 0px;">stealing data</strong> and then encrypting files. It also includes a <strong style="letter-spacing: 0px;">custom wiper tool</strong> to <strong style="letter-spacing: 0px;">erase</strong> traces of the ransomware executable, making it harder to investigate.</li></ul></h5>
<p></p>
<p></p>
<p></p>
<p></p>
<p></p>
<p></p>
<h1 class="wp-block-heading">Recommendations</h1>
<p></p>
<h3 class="wp-block-heading">All Fortinet administrators/users are urged to update their products as mentioned below:</h3>
<p></p>
<h3 class="wp-block-heading">a. &nbsp; &nbsp; &nbsp; &nbsp; Upgrade FortiOS to version 7.0.17 or later.</h3>
<p></p>
<h3 class="wp-block-heading">b. &nbsp; &nbsp; &nbsp; &nbsp; Upgrade FortiProxy to version 7.2.13 or later or 7.0.20.</h3>
<p></p>
<h3 class="wp-block-heading">c. &nbsp; &nbsp; &nbsp; &nbsp; Remove the firewall’s web-based management interface from public internet exposure.</h3>
<p></p>
<h3 class="wp-block-heading">d. &nbsp; &nbsp; &nbsp; &nbsp; Regularly review administrative accounts for unauthorized additions or changes.</h3>
<p></p>
<h3 class="wp-block-heading">e. &nbsp; &nbsp; &nbsp; &nbsp; Monitor for unexpected configuration changes and unauthorized login attempts.</h3>
<p></p>
<h3 class="wp-block-heading">f.&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Be vigilant for indicators of compromise, such as unusual automation tasks or unexpected VPN connections.</h3>
<p></p>
<h3 class="wp-block-heading">g. &nbsp; &nbsp; &nbsp; &nbsp; Implement strict network segmentation to limit lateral movement opportunities for attackers.</h3>
<p></p>
<h3 class="wp-block-heading">h. &nbsp; &nbsp; &nbsp; &nbsp; Enforce multi-factor authentication (MFA) for all administrative access.</h3>
<p></p>
<h1 class="wp-block-heading">Conclusion</h1>
<p></p>
<p class="wp-block-paragraph">The recent activities of Mora_001 highlight the growing sophistication of ransomware actors tied to LockBit, particularly their ability to exploit critical vulnerabilities in widely used security products. The deployment of SuperBlack ransomware demonstrates the severe risks organizations face when systems remain unpatched or exposed. Timely updates, strict access controls, and proactive monitoring are essential to defend against these evolving threats. Organizations should treat this advisory with urgency, as the combination of double extortion and stealthy persistence techniques makes this campaign especially dangerous. Staying vigilant and applying Fortinet’s recommended patches is the most effective defense against these attacks</p>
<p></p>
<p class="wp-block-paragraph"></p>]]></content:encoded>
					
					<wfw:commentRss>https://pk-360.com/new-cybersecurity-warning-ransomware-actors-tied-to-lockbit/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>Protecting Your Digital World: The Importance of Information Security</title>
		<link>https://pk-360.com/importance-of-information-security/</link>
					<comments>https://pk-360.com/importance-of-information-security/#respond</comments>
		
		<dc:creator><![CDATA[Haider]]></dc:creator>
		<pubDate>Mon, 04 Aug 2025 18:14:41 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[best practices for security]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[cyber awareness]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity tips]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[digital safety]]></category>
		<category><![CDATA[digital world protection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[internet safety]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[malware protection]]></category>
		<category><![CDATA[online privacy]]></category>
		<category><![CDATA[phishing prevention]]></category>
		<category><![CDATA[prevent cyber attacks]]></category>
		<category><![CDATA[protect sensitive data]]></category>
		<category><![CDATA[ransomware defense]]></category>
		<category><![CDATA[secure passwords]]></category>
		<guid isPermaLink="false">https://pk-360.com/?p=92</guid>

					<description><![CDATA[The importance of Information Security in today&#8217;s digital age, information security is more crucial than ever. With the rise of cyber threats and data breaches, protecting sensitive information has become a top priority for individuals and organizations alike. Information security refers to the practices and technologies designed to safeguard digital information from unauthorized access, use,]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The importance of Information Security in today&#8217;s digital age, information security is more crucial than ever. With the rise of cyber threats and data breaches, protecting sensitive information has become a top priority for individuals and organizations alike. Information security refers to the practices and technologies designed to safeguard digital information from unauthorized access, use, disclosure, disruption, modification, or destruction.</p>



<p class="has-large-font-size wp-block-paragraph"><strong>Why is Information Security Important?</strong></p>



<ul class="wp-block-list">
<li><strong>Protects sensitive data: </strong>Information security helps protect personal and confidential data, such as financial information, passwords, and personal identifiable information.</li>



<li><strong>Prevents cyber attacks:</strong> Robust security measures can prevent cyber attacks, such as malware, phishing, and ransomware, which can compromise systems and data.</li>



<li><strong>Maintains trust:</strong> Effective information security practices help maintain trust with customers, partners, and stakeholders.</li>
</ul>



<p class="has-large-font-size wp-block-paragraph"><strong>Best Practices for Information Security</strong></p>



<ul class="wp-block-list">
<li><strong>Use strong passwords: </strong>Use complex and unique passwords for all accounts.</li>



<li><strong>Keep software up-to-date:</strong> Regularly update software and systems to patch vulnerabilities.</li>



<li><strong>Use encryption:</strong> Encrypt sensitive data to protect it from unauthorized access.</li>



<li><strong>Be cautious with emails and links: </strong>Avoid suspicious emails and links that can lead to phishing or malware attacks.</li>
</ul>



<p class="has-large-font-size wp-block-paragraph"><strong>Conclusion</strong></p>



<p class="wp-block-paragraph">Information security is a critical aspect of our digital lives. By understanding the importance of information security and implementing best practices, individuals and organizations can protect their sensitive data and prevent cyber attacks. Stay safe online by prioritizing information security!</p>



<ul class="wp-block-social-links is-layout-flex wp-block-social-links-is-layout-flex"></ul>



<p class="wp-block-paragraph"></p>
<div class="pvc_clear"></div><p id="pvc_stats_92" class="pvc_stats all  " data-element-id="92" style=""><i class="pvc-stats-icon large" aria-hidden="true"><svg xmlns="http://www.w3.org/2000/svg" version="1.0" viewBox="0 0 502 315" preserveAspectRatio="xMidYMid meet"><g transform="translate(0,332) scale(0.1,-0.1)" fill="" stroke="none"><path d="M2394 3279 l-29 -30 -3 -207 c-2 -182 0 -211 15 -242 39 -76 157 -76 196 0 15 31 17 60 15 243 l-3 209 -33 29 c-26 23 -41 29 -80 29 -41 0 -53 -5 -78 -31z"/><path d="M3085 3251 c-45 -19 -58 -50 -96 -229 -47 -217 -49 -260 -13 -295 52 -53 146 -42 177 20 16 31 87 366 87 410 0 70 -86 122 -155 94z"/><path d="M1751 3234 c-13 -9 -29 -31 -37 -50 -12 -29 -10 -49 21 -204 19 -94 39 -189 45 -210 14 -50 54 -80 110 -80 34 0 48 6 76 34 21 21 34 44 34 59 0 14 -18 113 -40 219 -37 178 -43 195 -70 221 -36 32 -101 37 -139 11z"/><path d="M1163 3073 c-36 -7 -73 -59 -73 -102 0 -56 133 -378 171 -413 34 -32 83 -37 129 -13 70 36 67 87 -16 290 -86 209 -89 214 -129 231 -35 14 -42 15 -82 7z"/><path d="M3689 3066 c-15 -9 -33 -30 -42 -48 -48 -103 -147 -355 -147 -375 0 -98 131 -148 192 -74 13 15 57 108 97 206 80 196 84 226 37 273 -30 30 -99 39 -137 18z"/><path d="M583 2784 c-38 -19 -67 -74 -58 -113 9 -42 211 -354 242 -373 16 -10 45 -18 66 -18 51 0 107 52 107 100 0 39 -1 41 -124 234 -80 126 -108 162 -133 173 -41 17 -61 16 -100 -3z"/><path d="M4250 2784 c-14 -9 -74 -91 -133 -183 -95 -150 -107 -173 -107 -213 0 -55 33 -94 87 -104 67 -13 90 8 211 198 130 202 137 225 78 284 -27 27 -42 34 -72 34 -22 0 -50 -8 -64 -16z"/><path d="M2275 2693 c-553 -48 -1095 -270 -1585 -649 -135 -104 -459 -423 -483 -476 -23 -49 -22 -139 2 -186 73 -142 361 -457 571 -626 285 -228 642 -407 990 -497 242 -63 336 -73 660 -74 310 0 370 5 595 52 535 111 1045 392 1455 803 122 121 250 273 275 326 19 41 19 137 0 174 -41 79 -309 363 -465 492 -447 370 -946 591 -1479 653 -113 14 -422 18 -536 8z m395 -428 c171 -34 330 -124 456 -258 112 -119 167 -219 211 -378 27 -96 24 -300 -5 -401 -72 -255 -236 -447 -474 -557 -132 -62 -201 -76 -368 -76 -167 0 -236 14 -368 76 -213 98 -373 271 -451 485 -162 444 86 934 547 1084 153 49 292 57 452 25z m909 -232 c222 -123 408 -262 593 -441 76 -74 138 -139 138 -144 0 -16 -233 -242 -330 -319 -155 -123 -309 -223 -461 -299 l-81 -41 32 46 c18 26 49 83 70 128 143 306 141 649 -6 957 -25 52 -61 116 -79 142 l-34 47 45 -20 c26 -10 76 -36 113 -56z m-2057 25 c-40 -58 -105 -190 -130 -263 -110 -324 -59 -707 132 -981 25 -35 42 -64 37 -64 -19 0 -241 119 -326 174 -188 122 -406 314 -532 468 l-58 71 108 103 c185 178 428 349 672 473 66 33 121 60 123 61 2 0 -10 -19 -26 -42z"/><path d="M2375 1950 c-198 -44 -350 -190 -395 -379 -18 -76 -8 -221 19 -290 114 -284 457 -406 731 -260 98 52 188 154 231 260 27 69 37 214 19 290 -38 163 -166 304 -326 360 -67 23 -215 33 -279 19z"/></g></svg></i> <img decoding="async" width="16" height="16" alt="Loading" src="https://pk-360.com/wp-content/plugins/page-views-count/ajax-loader-2x.gif" border=0 /></p><div class="pvc_clear"></div>]]></content:encoded>
					
					<wfw:commentRss>https://pk-360.com/importance-of-information-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
