Security News

Patch procrastination leaves 50,000 Fortinet firewalls vulnerable to zero-day
2025-01-21 18:45

Seven days after disclosure and little action taken, data shows Fortinet customers need to get with the program and apply the latest updates as nearly 50,000 management interfaces are still...

Week in review: AWS S3 data encrypted without ransomware, data of 15k Fortinet firewalls leaked
2025-01-19 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Attackers are encrypting AWS S3 data without using ransomware A ransomware gang dubbed Codefinger...

Fortinet: FortiGate config leaks are genuine but misleading
2025-01-17 18:32

Competition hots up with Ivanti over who can have the worst start to a year Fortinet has confirmed that previous analyses of records leaked by the Belsen Group are indeed genuine FortiGate configs...

Configuration files for 15,000 Fortinet firewalls leaked. Are yours among them?
2025-01-16 11:01

A threat actor has leaked configuration files (aka configs) for over 15,000 Fortinet Fortigate firewalls and associated admin and user credentials. The collection has been leaked on Monday and...

Fortinet fixes FortiOS zero-day exploited by attackers for months (CVE-2024-55591)
2025-01-14 17:15

Fortinet has patched an authentication bypass vulnerability (CVE-2024-55591) affecting its FortiOS firewalls and FortiProxy web gateways that has been exploited as a zero-day by attackers to...

Fortinet warns of auth bypass zero-day exploited to hijack firewalls
2025-01-14 15:24

​Attackers are exploiting a new authentication bypass zero-day vulnerability in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. [...]

Fortinet Warns of New Zero-Day Used in Attacks on Firewalls with Exposed Interfaces
2025-01-14 09:13

Threat hunters are calling attention to a new campaign that has targeted Fortinet FortiGate firewall devices with management interfaces exposed on the public internet. "The campaign involved...

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used
2025-01-14 01:43

Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg Miscreants running a "mass exploitation campaign" against Fortinet firewalls, which peaked in December, may be using an...

Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools
2024-12-20 06:25

A now-patched critical security flaw impacting Fortinet FortiClient EMS is being exploited by malicious actors as part of a cyber campaign that installed remote desktop software such as AnyDesk...

Fortinet warns of FortiWLM bug giving hackers admin privileges
2024-12-19 17:24

Fortinet has disclosed a critical vulnerability in Fortinet Wireless Manager (FortiWLM) that allows remote attackers to take over devices by executing unauthorized code or commands through...