Security News

Fortinet VPN design flaw hides successful brute-force attacks
2024-11-21 14:38

A design flaw in the Fortinet VPN server's logging mechanism can be leveraged to conceal the successful verification of credentials during a brute-force attack without tipping off defenders of...

China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer
2024-11-19 23:02

No word on when or if the issue will be fixed Chinese government-linked snoops are exploiting a zero-day bug in Fortinet's Windows VPN client to steal credentials and other information, according...

Chinese hackers exploit Fortinet VPN zero-day to steal credentials
2024-11-18 21:20

Chinese threat actors use a custom post-exploitation toolkit named 'DeepData' to exploit a zero-day vulnerability in Fortinet's FortiClient Windows VPN client that steal credentials. [...]

Warning: DEEPDATA Malware Exploiting Unpatched Fortinet Flaw to Steal VPN Credentials
2024-11-16 06:25

A threat actor known as BrazenBamboo has exploited an unresolved security flaw in Fortinet's FortiClient for Windows to extract VPN credentials as part of a modular framework called DEEPDATA....

Fortinet patches VPN app flaw that could give rogue users, malware a privilege boost
2024-11-14 22:22

Plus a bonus hard-coded local API key A now-patched, high-severity bug in Fortinet's FortiClient VPN application potentially allows a low-privilege rogue user or malware on a vulnerable Windows...

Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE
2024-10-27 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Fortinet releases patches for publicly undisclosed critical FortiManager vulnerability In the last...

Fortinet FortiManager flaw exploited in zero-day attacks (CVE-2024-47575)
2024-10-24 09:04

Fortinet has finally made public information about CVE-2024-47575, a critical FortiManager vulnerability that attackers have exploited as a zero-day. About CVE-2024-47575 CVE-2024-47575 is a...

Fortinet Warns of Critical Vulnerability in FortiManager Under Active Exploitation
2024-10-24 06:23

Fortinet has confirmed details of a critical security flaw impacting FortiManager that has come under active exploitation in the wild. Tracked as CVE-2024-47575 (CVSS score: 9.8), the...

Mandiant says new Fortinet flaw has been exploited since June
2024-10-24 05:05

A new Fortinet FortiManager flaw dubbed "FortiJump" and tracked as CVE-2024-47575 has been exploited since June 2024 in zero-day attacks on over 50 servers, according to a new report by Mandiant. [...]

Fortinet warns of new critical FortiManager flaw used in zero-day attacks
2024-10-23 15:05

Fortinet publicly disclosed today a critical FortiManager API vulnerability, tracked as CVE-2024-47575, that was exploited in zero-day attacks to steal sensitive files containing configurations,...