fortinet

CISA Adds Fortinet and Microsoft Flaws to Exploited Vulnerabilities List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added critical vulnerabilities affecting Fortinet FortiSandbox and Microsoft SharePoint to its Known Exploited Vulnerabilities catalog. The flaws include OS command injection in FortiSandbox and a deserialization vulnerability in SharePoint that allows for remote code execution without authentication. Microsoft has confirmed active exploitation of the SharePoint flaw.

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
A widespread issue dubbed FortiBleed has been reported, involving the large-scale exposure and abuse of credentials targeting internet-facing FortiGate devices. This problem stems from credential reuse and brute-force attacks, rather than a new vulnerability. The risk is particularly high for devices lacking multi-factor authentication or those with previously compromised credentials.

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
A campaign dubbed FortiBleed has exposed administrative and VPN credentials for over 73,000 FortiGate systems. The compromised data has been offered for sale by at least two threat actors, one of whom is considered credible by researchers, while the other is suspected of attempting to re-extort victims. The exposed credentials impact organizations across various sectors, including government and critical infrastructure.

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
The UK's National Cyber Security Centre has released guidance for organizations utilizing Fortinet products. This advisory comes in response to a widespread campaign that has been observed targeting Fortinet firewalls and VPN gateways.