Tag “Fortinet”

Microsoft Releases Patches for 51 Vulnerabilities, Featuring a Critical MSMQ Flaw

Microsoft Addresses 51 Vulnerabilities in June Patch Tuesday Update In its latest Patch Tuesday update for June 2024, Microsoft has rolled out security updates to address 51 vulnerabilities across its products. Among these, one vulnerability has been classified as Critical, while the remaining 50 are deemed Important. This release also…

Read MoreMicrosoft Releases Patches for 51 Vulnerabilities, Featuring a Critical MSMQ Flaw

UNC3886 Employs Fortinet and VMware 0-Day Exploits Alongside Stealth Techniques for Prolonged Espionage

Chinese Cyber Espionage Group Exploits Vulnerabilities in Major Tech Platforms A sophisticated cyber espionage campaign linked to the Chinese threat actor UN3886 has been identified, involving the exploitation of zero-day vulnerabilities within widely used technologies such as Fortinet, Ivanti, and VMware systems. Recent findings highlight that the attackers have been…

Read MoreUNC3886 Employs Fortinet and VMware 0-Day Exploits Alongside Stealth Techniques for Prolonged Espionage

UNC5820 Exploits Zero-Day Vulnerability in FortiManager (CVE-2024-47575)

In a troubling development for cybersecurity, Fortinet, in collaboration with Mandiant, has uncovered a widespread exploitation of FortiManager devices linked to CVE-2024-47575. This vulnerability has compromised over 50 systems across various sectors, with the threat group known as UNC5820 leveraging the flaw to facilitate data theft and unauthorized access. The…

Read MoreUNC5820 Exploits Zero-Day Vulnerability in FortiManager (CVE-2024-47575)

FortiGate Administrators Report Active Exploitation of 0-Day Vulnerability, Vendor Remains Silent.

Fortinet, a prominent provider of network security solutions, has recently come under scrutiny for concealing a significant vulnerability that has reportedly been exploited by attackers to execute unauthorized code on servers belonging to sensitive organizations. This silence persisted for over a week, raising concerns among users and cybersecurity experts alike…

Read MoreFortiGate Administrators Report Active Exploitation of 0-Day Vulnerability, Vendor Remains Silent.

U.S. Federal Authorities Disable China-Linked “KV-Botnet” Aimed at SOHO Routers

The U.S. government announced on Wednesday that it has taken significant action to disrupt a botnet composed of hundreds of small office and home office (SOHO) routers based in the United States. This botnet, referred to as the KV-botnet, is linked to Volt Typhoon, a state-sponsored threat actor associated with…

Read MoreU.S. Federal Authorities Disable China-Linked “KV-Botnet” Aimed at SOHO Routers

Microsoft’s July Update Addresses 143 Vulnerabilities, Including Two Currently Under Attack

Microsoft has announced the release of security patches addressing a staggering 143 vulnerabilities as part of its latest monthly updates. Among these issues, two have been confirmed to be actively exploited, heightening concerns for organizations relying on Microsoft software. The updates, which categorize five vulnerabilities as Critical, 136 as Important,…

Read MoreMicrosoft’s July Update Addresses 143 Vulnerabilities, Including Two Currently Under Attack

As Cybercriminals Leverage AI, Here Are 5 Essential Steps Every Organization Should Take

Artificial Intelligence (AI) is transforming society in numerous beneficial ways, yet it has also become a tool exploited by cybercriminals to perpetrate nefarious activities. Threat actors, both seasoned and novice, leverage AI to enhance their data-gathering capabilities and to generate convincing phishing communications, thereby streamlining their malicious endeavors. As a…

Read MoreAs Cybercriminals Leverage AI, Here Are 5 Essential Steps Every Organization Should Take

Zero-Day Alert: Critical Vulnerability in Palo Alto Networks PAN-OS is Under Active Exploitation

Palo Alto Networks has issued an urgent warning regarding a critical vulnerability affecting its PAN-OS software utilized in GlobalProtect gateways, noting that this flaw is currently being actively exploited in the wild. Designated as CVE-2024-3400, this vulnerability carries a maximum CVSS score of 10.0, underscoring its potential severity and urgency…

Read MoreZero-Day Alert: Critical Vulnerability in Palo Alto Networks PAN-OS is Under Active Exploitation

State-Sponsored Hackers Leverage Two Cisco Zero-Day Vulnerabilities for Espionage Activities

A recent malware campaign has targeted Cisco networking equipment, exploiting two previously unknown vulnerabilities identified as zero-day flaws to deliver customized malware and conduct covert data collection in targeted environments. Cisco Talos, naming this operation “ArcaneDoor,” has attributed the attacks to UAT4356, an advanced state-sponsored group also known as Storm-1849…

Read MoreState-Sponsored Hackers Leverage Two Cisco Zero-Day Vulnerabilities for Espionage Activities