TechCrunch News 01月15日
Hackers are exploiting a new Fortinet firewall bug to breach company networks
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

安全研究人员指出,黑客正在利用Fortinet防火墙中新发现的漏洞入侵企业网络。Fortinet已确认该高危漏洞CVE-2024-55591正被利用。尽管官方已发布补丁,但研究人员警告称,黑客自去年12月起就已开始大规模利用此零日漏洞。此次事件是企业安全产品漏洞被利用的最新例证。网络安全公司Arctic Wolf表示,他们观察到针对暴露在公网的FortiGate防火墙设备的“大规模利用”活动。初步迹象显示,黑客试图在短时间内攻击大量设备。目前尚不清楚攻击者身份,但有研究员指出,该漏洞可能正被勒索软件团伙利用。

⚠️ Fortinet防火墙的CVE-2024-55591漏洞被确认为高危漏洞,且已被黑客在野外大规模利用,对企业网络安全构成严重威胁。

🚨 黑客利用此零日漏洞的时间可追溯至去年12月,在Fortinet发布补丁之前就已经开始攻击,表明黑客行动迅速且隐蔽。

🛡️ Arctic Wolf公司的研究表明,大量暴露在公网的FortiGate防火墙设备受到了影响,初步观察到数十起入侵事件,实际受影响设备数量可能更多。

💰 有网络安全研究员指出,该漏洞可能正在被勒索软件团伙利用,这意味着受攻击的企业可能面临数据泄露和巨额赎金的风险。

Security researchers say malicious hackers have been exploiting a newly discovered vulnerability in Fortinet firewalls to break into corporate and enterprise networks.

In an advisory published Tuesday, security product maker Fortinet confirmed that a critical-rated vulnerability in its FortiGate firewalls, tracked as CVE-2024-55591, is “being exploited in the wild.” 

Fortinet made patches available, but security researchers have warned that hackers have been mass-exploiting the vulnerability as a zero-day — meaning before Fortinet was aware of the vulnerability and made fixes available — since December.

This is the latest example of hackers exploiting a vulnerability in a popular enterprise security product designed to protect corporate networks from intruders. News of the Fortinet bug lands days after it was revealed that attackers are exploiting a separate zero-day flaw in Ivanti VPN servers that allows access to customers’ networks.

Cybersecurity company Arctic Wolf said in a blog post last week that its researchers observed a recent “mass exploitation” campaign affecting Fortinet FortiGate firewall devices with management interfaces exposed to the public internet.

Stefan Hostetler, lead threat intelligence researcher at Arctic Wolf, confirmed to TechCrunch that this observed exploitation is linked to the newly confirmed CVE-2024-55591 vulnerability in Fortinet firewalls. 

Hostetler told TechCrunch that Arctic Wolf had “observed a cluster of intrusions affecting Fortinet devices in the tens,” but notes that this only represents a “limited sample compared to the total actual number of devices that were likely affected.”

“The evidence points to an effort to exploit a large number of devices within a narrow timeframe,” added Hostetler.

When reached by TechCrunch, Fortinet spokesperson Tiffany Curci declined to say how many Fortinet customers were compromised as a result of this hacking campaign, but said that the company was “proactively communicating with customers.”

It’s also unclear who is behind the attacks on Fortinet firewalls, but cybersecurity researcher Kevin Beaumont writes on Mastodon that the vulnerability is “under exploitation by a ransomware operator.” 

Hostetler said that ransomware attacks exploiting the bug are “not off the table,” noting that in previous research, Arctic Fox “observed affiliates of ransomware groups such as Akira and Fog using some of the same network providers to establish VPN connectivity.”

In a brief statement on Tuesday, U.S. cybersecurity CISA urged Fortinet customers to update any affected devices.

In September, Fortinet disclosed a breach involving customer data after an attacker accessed “a limited number of files” stored on a third-party shared cloud drive belonging to the organization.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Fortinet 防火墙漏洞 网络安全 零日攻击 勒索软件
相关文章