Hackers Target Fortinet Firewalls to Deploy Ransomware

Hackers Target Fortinet Firewalls to Deploy Ransomware
Security researchers report that hackers associated with the LockBit gang are exploiting vulnerabilities in Fortinet firewalls to deploy a new ransomware strain named 'SuperBlack'. The vulnerabilities, identified as CVE-2024-55591 and CVE-2025-24472, have been actively exploited since December 2024, despite patches being released in January. The attackers have been observed selectively encrypting sensitive data after exfiltration. Analysts suggest that these attacks target organizations that failed to implement necessary security measures. The connection to LockBit indicates a possible collaboration or shared tactics among cybercriminals.