Tag “Fortinet”

CISA Alerts About Major Fortinet Vulnerability as Palo Alto and Cisco Release Emergency Security Updates

On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the addition of a critical security vulnerability affecting Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog. This action was taken in light of evidence indicating ongoing exploitation of this flaw. Identified as CVE-2024-23113, this vulnerability has a CVSS…

Read MoreCISA Alerts About Major Fortinet Vulnerability as Palo Alto and Cisco Release Emergency Security Updates

Nation-State Hackers Target Ivanti CSA Vulnerabilities for Network Breaches

A suspected nation-state actor has been detected exploiting three critical vulnerabilities in the Ivanti Cloud Service Appliance (CSA), leveraging these zero-day flaws to conduct a series of targeted cyberattacks. According to Fortinet’s FortiGuard Labs, these vulnerabilities allowed attackers to gain unauthorized access to the CSA, enumerate users, and access their…

Read MoreNation-State Hackers Target Ivanti CSA Vulnerabilities for Network Breaches

CISA Includes ScienceLogic SL1 Vulnerability in Exploited Catalog Following Recent Zero-Day Attack

On Monday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially included a significant security vulnerability affecting ScienceLogic SL1 in its Known Exploited Vulnerabilities (KEV) list. This action comes in response to confirmed instances of active exploitation as a zero-day vulnerability. The flaw, designated as CVE-2024-9537 (scoring 9.3 on the…

Read MoreCISA Includes ScienceLogic SL1 Vulnerability in Exploited Catalog Following Recent Zero-Day Attack

Fortinet Alerts Users to Critical Vulnerability in FortiManager Currently Being Actively Exploited

Fortinet Confirms Critical Vulnerability in FortiManager Under Active Exploitation Fortinet has identified a significant security vulnerability affecting its FortiManager product, designated as CVE-2024-47575, with a high CVSS score of 9.8. This vulnerability, also referred to as FortiJump, relates to the FGFM protocol utilized for communication between FortiGate devices and FortiManager.…

Read MoreFortinet Alerts Users to Critical Vulnerability in FortiManager Currently Being Actively Exploited

Top 30 Critical Security Vulnerabilities Frequently Targeted by Hackers

In a recent joint advisory, intelligence agencies from Australia, the U.K., and the U.S. have highlighted critical vulnerabilities that were actively exploited during 2020 and 2021. This report underscores how swiftly threat actors can capitalize on publicly disclosed weaknesses in software, posing a significant risk to various organizations worldwide. The…

Read MoreTop 30 Critical Security Vulnerabilities Frequently Targeted by Hackers

Cisco Releases Critical Patch for ASA and FTD Software Vulnerability Under Active Exploit

Cisco Issues Critical Updates for Vulnerability in Adaptive Security Appliance Cisco Systems announced today that it has rolled out urgent security updates to address a significant vulnerability in its Adaptive Security Appliance (ASA) that has been actively exploited. This issue could result in a denial-of-service (DoS) condition, impacting the Remote…

Read MoreCisco Releases Critical Patch for ASA and FTD Software Vulnerability Under Active Exploit

Microsoft Addresses 90 New Vulnerabilities, Including Actively Exploited NTLM and Task Scheduler Issues

On November 12, 2024, Microsoft disclosed that two significant security vulnerabilities affecting Windows NT LAN Manager (NTLM) and Task Scheduler have been actively exploited in the wild. These vulnerabilities were part of the November Patch Tuesday update, which addressed a total of 90 security flaws across Microsoft products. Among the…

Read MoreMicrosoft Addresses 90 New Vulnerabilities, Including Actively Exploited NTLM and Task Scheduler Issues

Alert: DEEPDATA Malware Targets Unpatched Fortinet Vulnerability to Harvest VPN Credentials

A security vulnerability in Fortinet’s FortiClient for Windows has been exploited by the threat group known as **BrazenBamboo**, allowing them to extract VPN credentials using a modular framework named **DEEPDATA**. This exploitation was disclosed by Volexity, which reported the zero-day vulnerability’s emergence in July 2024. BrazenBamboo is also linked to…

Read MoreAlert: DEEPDATA Malware Targets Unpatched Fortinet Vulnerability to Harvest VPN Credentials

Fortinet Faces Securities Fraud Allegations Related to Firewall Projections

Litigation, Network Firewalls, Network Access Control, Security Operations Pension Funds Accuse Fortinet of Misleading Market with Optimistic Refresh Forecast Michael Novinson (MichaelNovinson) • October 24, 2025 A pair of class action lawsuits have recently been filed against Fortinet, alleging violations of federal securities laws through misleading claims about a “record”…

Read MoreFortinet Faces Securities Fraud Allegations Related to Firewall Projections