Tag “Fortinet”

Coupang Breach Triggers Leadership Restructuring

Cybercrime, Fraud Management & Cybercrime, Incident & Breach Response Also: Texas AG Sues Smart TV Manufacturers, Fortinet SSO Flaws Pooja Tikekar (@PoojaTikekar) • December 18, 2025 Image: Shutterstock/ISMG This week, Information Security Media Group presents a roundup of significant cybersecurity breaches globally. Major developments include a leadership transition at Coupang,…

Read MoreCoupang Breach Triggers Leadership Restructuring

A Google Drive Vulnerability Could Enable Attackers to Coerce You into Installing Malware

A recently uncovered vulnerability in Google Drive presents a significant risk, potentially allowing cybercriminals to distribute malware disguised as legitimate files. This largely unaddressed security oversight enables attackers to leverage Google Drive’s file version management feature, resulting in higher success rates for spear-phishing schemes. The flaw, which Google is reportedly…

Read MoreA Google Drive Vulnerability Could Enable Attackers to Coerce You into Installing Malware

CISA Identifies 6 Vulnerabilities: Apple, Apache, Adobe, D-Link, and Joomla at Risk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included six new security vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog, citing clear indications of ongoing exploitation. This move emphasizes the necessity for organizations to remain vigilant and proactive in their cybersecurity measures. Among the newly flagged vulnerabilities is…

Read MoreCISA Identifies 6 Vulnerabilities: Apple, Apache, Adobe, D-Link, and Joomla at Risk

Microsoft’s January 2024 Windows Update Addresses 48 New Vulnerabilities

In a significant update released for January 2024, Microsoft has patched a total of 48 security vulnerabilities across its software ecosystem. This month’s Patch Tuesday includes two flaws classified as Critical and 46 as Important. Notably, there are no indications that any of these vulnerabilities are being actively exploited or…

Read MoreMicrosoft’s January 2024 Windows Update Addresses 48 New Vulnerabilities

Emergence of New Ransomware Gangs: Albabat, Kasseika, and Kuiper Leverage Rust and Go

Cybersecurity researchers have discovered a new variant of the Phobos ransomware family named Faust. This iteration was documented by Fortinet FortiGuard Labs, which detailed its dissemination method involving a Microsoft Excel document (.XLAM) that contains a VBA script capable of executing malicious actions. The attack initiates when the victim opens…

Read MoreEmergence of New Ransomware Gangs: Albabat, Kasseika, and Kuiper Leverage Rust and Go

Fortinet Alerts Users to Critical FortiOS SSL VPN Vulnerability Possibly Being Actively Exploited

Fortinet has recently uncovered a significant security vulnerability in its FortiOS SSL VPN, identified as CVE-2024-21762, which is currently believed to be actively exploited in the wild. This flaw, with a CVSS score of 9.6, poses a serious risk by enabling the execution of arbitrary code and commands by outside…

Read MoreFortinet Alerts Users to Critical FortiOS SSL VPN Vulnerability Possibly Being Actively Exploited

Microsoft Releases Fixes for 73 Vulnerabilities, Including Two Windows Zero-Day Exploits

In its February 2024 Patch Tuesday updates, Microsoft has issued fixes for 73 security vulnerabilities across its software ecosystem, including two zero-day flaws currently under active exploitation. Among these vulnerabilities, five have been categorized as Critical and 65 as Important, while three have a Moderate severity rating. This release also…

Read MoreMicrosoft Releases Fixes for 73 Vulnerabilities, Including Two Windows Zero-Day Exploits

Chinese Hackers Leveraging Ivanti VPN Vulnerabilities to Distribute New Malware

Recent investigations have uncovered two distinct cyber espionage groups allegedly linked to China: UNC5325 and UNC3886, both exploiting vulnerabilities in Ivanti Connect Secure VPN appliances. UNC5325 is reported to have utilized the critical vulnerability tracked as CVE-2024-21893, distributing various malware strains, including LITTLELAMB.WOOLTEA and PITDOG, among others. According to Mandiant,…

Read MoreChinese Hackers Leveraging Ivanti VPN Vulnerabilities to Distribute New Malware

Urgent: Apple Releases Critical Updates to Address Actively Exploited Zero-Day Vulnerabilities

Apple Releases Critical Security Updates to Address Exploited Vulnerabilities Apple has issued new security updates aimed at mitigating significant flaws in its operating systems, including vulnerabilities that have reportedly been exploited in the wild. The updates come in response to the discovery of two critical memory corruption issues affecting the…

Read MoreUrgent: Apple Releases Critical Updates to Address Actively Exploited Zero-Day Vulnerabilities