Marco Pedrinazzi

Exposed Fortinet Fortigate firewall interface leads to LockBit Ransomware (CVE-2024-55591)

InTheCyber got engaged in an incident response activity by an enterprise victim of LockBit3.0. The victim had no monitoring solution in place. Most of the logs on critical systems to analyze got encrypted by the threat actor and weak log retention policies did not allow us to reconstruct some dynamics of the attack. Phase 1: Exploitation of CVE-2024–55591 (Days 1–6)

Phase 2: A new threat actor? (Days 7–8)

Read the original article.