Ransomware Rodeo: Fortinet Flaws and GitHub Fiasco Unleash Cyber Chaos

CISA has confirmed that a critical vulnerability, CVE-2025-24472, in Fortinet products is being exploited by the ransomware group Mora_00. This flaw allows attackers to gain super-admin privileges, making it a hacker’s dream come true. Users are advised to patch up faster than a squirrel on espresso.

Pro Dashboard

Hot Take:

Another day, another cybersecurity vulnerability wreaking havoc on the digital playground. Fortinet and GitHub users, ever heard of patching? It’s like sunscreen for your software. Applying it may not make you look cool, but it’ll prevent some serious burns! Meanwhile, cybercriminals are out here playing leapfrog with vulnerabilities, and it’s up to us to stop them from winning the game. Let’s patch things up, literally and figuratively!

Key Points:

  • Critical vulnerability CVE-2025-24472 in Fortinet products exploited by ransomware group Mora_00.
  • Fortinet users advised to update to patched versions 7.0.17, 7.2.13, or 7.0.20.
  • CVE-2024-55591 also exploited, with ransomware strain ‘SuperBlack’ being deployed.
  • GitHub Action vulnerability CVE-2025-30066 impacted over 23,000 organizations.
  • Organizations urged to verify and update their GitHub Action frameworks immediately.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?