Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3. 1 score: 9. 8/CVSS v4 score: 9. 3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3. 21. 21 before 3. 30. 2 contains an unauthenticated remote code execution vulnerability that allows remote

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

8 Best Google Cloud (GCP) Security Tools for Every Business Size (2026)

Quick Answer: GCP security is a sequencing problem: Security Command Center Standard (included) plus ScoutSuite audits before any spend; Datadog or Sysdig where engineering already operates; Wiz when security hires need one ranked queue; Fortinet (Lacework) for anomaly-led detection; Prisma Cloud at program scale. And at every stage, service-account hygiene outperforms tool shopping. Google Cloud attracts engineering-led companies which is exactly why its security failures are so predictable: brilliant teams, sprawling service accounts, and an included Security Command Center tier that somehow never got enabled org-wide. This brief is an adoption sequence rather than a leaderboard: what to switch on before spending, which additions ride the tooling your engineers already trust, and which purchases genuinely require a security function to be worth their queues.

·CyberPress
Read →
Breaches & Ransomware
Emerging1 src

Security Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware UK Council Attack Linked to Mass Exploitation of SonicWall Flaw U. S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog More Capable AI, Not Enough Guardrails A New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World Harm U. S.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2025-25249  Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability • CVE-2026-19490  Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability • CVE-2026-87491  Google Chromium V8 Out of Bounds Write Vulnerability • CVE-2026-20079  Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-20079 (CVSS score of 10. 0) is an authentication bypass issue.

·Security Affairs
Read →
Vendors & Market
Emerging1 src

Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa. The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 2. The following CVEs are assigned: CVE-2026-84387.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2025-25249 - Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

·CISA KEV
Read →
Vulnerabilities & Patches
Emerging1 src

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA portal and the backend destination website. Tracked as CVE-2026-84393 and documented under advisory FG-IR-26-174, the issue was published on September 8, 2026, and carries a CVSSv3 score of 7.3. The vulnerability stems from an improper certificate validation weakness, classified as CWE-295, within the Agentless ZTNA portal component. Zero Trust Network Access portals are designed to broker secure, identity-verified connections between end users and internal applications without requiring a full VPN client.

·Cyber Security News
Read →
Threat Actors & Campaigns
Emerging1 src

Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware

An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) that turns compromised perimeter devices into long-term footholds for espionage and data theft. The SOCRadar Threat Research Unit (STRU) has identified, with high confidence, that threat actors are actively exploiting CVE-2025-25249 , a critical heap-based buffer overflow flaw affecting the cw_acd daemon in FortiOS and FortiSwitchManager. Rated 9.8 on the CVSSv3 scale, the vulnerability allows remote, unauthenticated attackers to execute arbitrary code by sending specially crafted requests to the CAPWAP Control service, which listens on UDP port 5246. Fortinet uses CAPWAP to manage wireless access points centrally, making the daemon reachable on many internet-facing FortiGate appliances.

·Cyber Security News
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Thegentlemen has just published a new victim : S A Chile

syachile. cl zoominfo. com/c/sa-chile/372625700 S&A Chile is a Chilean mission-critical IT integrator founded in 1989 by Peruvian-Palestinian immigrant Edward Seleme Chávez from his home dining room — today run by his daughters (2nd generation) after his death in 2024, HQ named after him in Providencia, Santiago. Its two moats: a 35+ year IBM Premier/Gold partnership (multiple IBM awards, incl. " Top Infrastructure Sales 2024") and its own Tier III datacenter — 100% uptime for 5+ consecutive years, triple ISO-certified (9001/20000/27001), 2 MW power, running on certified renewable energy (Colbún, 2026). Core services: colocation/hosting, cybersecurity (Fortinet SOC), backup/DR, private cloud, plus a new AI vertical on IBM watsonx (2025). Anchor client: Correos de Chile (national postal service) has outsourced its infrastructure to S&A since 2002.

·Ransomware.live
Read →
Vendors & Market
Emerging1 src

8 Managed Firewall Services: Who to Watch in 2026

The verdict: if you want the deepest expertise on the platform you own, buy the managed service from the vendor who built it Palo Alto or Fortinet. If you want independent operators who’ll manage whatever you already have, Secureworks and the global system integrators are the strongest options. If you’d rather stop owning firewalls altogether, Cato Networks is the cleanest path. Below, eight providers matched to the buyer each actually fits and two ownership changes that should shape any multi-year contract. A managed firewall service transfers day-to-day firewall operation policy changes, patching, monitoring, tuning, and incident response to a provider with a 24/7 security operations centre. Check These Two Things Before You Sign Anything Managed security contracts run three to five years.

·CyberPress
Read →
Policy & Regulation
Emerging1 src

8 Wireless / Wi-Fi Security Solutions: Our Top Picks by Use Case (2026)

The verdict: Fortinet is the best-value secure wireless for organizations that already own a firewall, Cisco Meraki is the easiest to manage across multiple sites, and HPE Aruba goes deepest where wireless security genuinely has to be enterprise-grade infrastructure . Below that, the right answer depends almost entirely on your environment a warehouse, a school, and a five-person office need different things, and this brief matches each option to the situation it actually fits. Wi-Fi security protects wireless networks through encryption, authentication, rogue access point detection, and device-level access policy — and in 2026 the encryption question is settled. The interesting decisions are about what a device can reach after it connects.

·CyberPress
Read →
Threat Actors & Campaigns
Emerging1 src

8 Network Sandboxing Solutions: Our Top Picks by Use Case (2026)

Bottom line up front: if you already own a Check Point, Palo Alto, or Fortinet firewall, your sandbox decision is largely made buy the subscription and get verdicts pushed to enforcement automatically. If you need to understand malware rather than merely block it, Recorded Future’s Triage or a self-hosted analysis platform serves you far better. And if you’re considering the open-source route, read the Cuckoo section carefully before you commit engineering time. Network sandboxing detonates unknown files and URLs in an isolated environment and watches what they do catching malware that has never been seen before and therefore has no signature to match against, strengthening overall enterprise cybersecurity infrastructure . Stage 1 — Work Out Which Problem You’re Solving These are two different products that get sold as one category.

·CyberPress
Read →
Policy & Regulation
Emerging1 src

Top 10 Best Managed Firewall Services in 2026

Palo Alto Networks scores highest in our 2026 evaluation of managed firewall service , with Fortinet close behind on breadth and value and Cato Networks leading on cloud-native delivery. A managed firewall service transfers day-to-day firewall operation policy changes, patching, monitoring, tuning, and incident response to a provider with a 24/7 SOC, so your team stops doing 2 a. m. rule changes. Here are the ten best, scored, with the ownership changes you must factor into a multi-year contract. The 2026 Managed Firewall Scorecard Rank Provider SOC & response (30%) Platform coverage (25%) Service model (20%) Global reach (15%) Value (10%) Total 1 Palo Alto Networks 9 8 9 9 7 8. 6 2 Fortinet 8 9 8 9 9 8. 5 3 Cato Networks 8 8 9 9 8 8. 4 4 Secureworks 10 8 8 8 7 8. 6 5 LevelBlue (AT&T) 9 9 8 9 7 8. 6 6 NTT Data 8 9 8 10 7 8. 4 7 Orange Cyberdefense 9 8 8 9 7 8.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

The Collective Cyber Defense letter wrote your next vendor questionnaire

Last week, more than 100 companies and organizations published an open letter calling for a rapid acceleration of cyber defense capabilities to combat the capabilities of AI. The list reads like a procurement catalog. Microsoft, Google, AWS, Cisco, IBM, CrowdStrike, Cloudflare, Anthropic, Okta and Fortinet are on it, alongside buyers like Mastercard, Visa and Capital One. The public signatory page has since passed 200 companies and organizations, with some such as 1Password, Sophos and Prophet Security, have already published posts of their own detailing their commitment to defenders. The explanations are worth sitting with. Letters turn into marketing assets faster than they become company concrete action. The buyers decide which one becomes reality. The diagnosis is correct I want to be careful about how the skepticism below reads, because the letter has the substance right.

·CyberScoop
Read →
Vulnerabilities & Patches
Emerging1 src

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs.

·Tenable Blog
Read →
Vendors & Market
Emerging1 src

Best Business VPN Solutions: Our Top Picks by Use Case (2026)

A business VPN gives remote staff encrypted access to internal systems but “which VPN is best” is the wrong question in 2026. The right question is whether you need a traditional VPN at all, or whether a zero-trust access service would serve you better We scored eight options across both camps and matched each to the buyer it actually fits, from a ten-person startup to a field workforce on unreliable mobile connections. Best Business VPN by Use Case — At a Glance Your situation Our pick Score Existing Fortinet firewalls Fortinet 8. 5 Large enterprise, Cisco estate Cisco Secure Client (AnyConnect) 8. 2 Field workforce on poor mobile coverage Absolute (NetMotion) 8. 4 Small team wanting the simplest setup Tailscale 8. 6 SMB wanting managed cloud VPN NordLayer 8. 0 Palo Alto enterprise estate Palo Alto GlobalProtect 8. 1 Self-hosted and full control OpenVPN Access Server 7.

·CyberPress
Read →
AI Security
Emerging1 src

Fortinet Acquires AI Security Company Virtue AI

Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai ‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module on top. “FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot . The name derives from the hardcoded string “evooo1” found in every binary.” reads the report published by Fortinet.

·Security Affairs
Read →
AI Security
Emerging1 src

Fortinet expands AI security portfolio with Virtue AI acquisition

Fortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise. The acquisition builds on Fortinet’s existing AI security portfolio, which includes the FortiGate Hyperscale Firewall. As organizations deploy AI applications and autonomous agents, their attack surface expands beyond networks, users, endpoints, applications, and cloud workloads. It now includes prompts, models, agents, Model Context Protocol (MCP) tools, application programming interface (API) calls, and AI infrastructure. Organizations … More → The post Fortinet expands AI security portfolio with Virtue AI acquisition appeared first on Help Net Security .

·Help Net Security
Read →
Threat Actors & Campaigns
Emerging1 src

Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices

A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that reaches internet-facing edge systems by exploiting known flaws and attempting weak SSH logins. Its operators can then issue commands through an encrypted control channel. The campaign is more than another basic denial-of-service operation. It combines code drawn from the leaked Mirai framework with proxy, credential-sniffing, file-transfer, and exploit functions. That mix gives intruders several ways to use a single compromised device and mirrors recent Mirai botnet trends toward broader abuse. Fortinet analysts identified the malware after seeing active exploitation attempts against a range of edge devices.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 Stories

This week’s roundup covers a record-setting Microsoft Patch Tuesday, an actively exploited Cisco firewall zero-day, a Lazarus-linked Windows kernel bug, and critical flaws across TP-Link, Palo Alto Networks, Fortinet, and VMware — plus a first-of-its-kind autonomous AI agent “hack” and a DEF CON in-flight Wi-Fi scare. Ransomware & Threat Actor Campaigns Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA A joint FBI, CISA, NSA, and South Korean advisory has exposed the Gunra ransomware group, a Conti-derived double-extortion operation that emerged in April 2025 and has since matured into a full ransomware-as-a-service model rebranded as “Golden Community.”

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

FortiWeb Flaw Lets Unauthenticated Attackers Log In With Random Username and Password

Fortinet has released security updates for a critical FortiWeb authentication vulnerability that could allow a remote, unauthenticated attacker to log in to the web application firewall using a random username and password. Tracked as CVE-2026-26035, the flaw could expose graphical management and command-line administrative functions to unauthorized access. The vulnerability is classified as improper authentication, or CWE-287. Instead of requiring a stolen password, a valid administrator account, or conventional brute-force activity, exploitation may allow an attacker to submit arbitrary credentials that the affected authentication workflow incorrectly accepts. FortiWeb Flaw Lets Unauthenticated Attackers Log In According to Fortinet’s advisory , the issue is associated with Remote RADIUS Type administrator accounts with the wildcard option enabled.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

Fortinet Patches Multiple Authentication Vulnerabilities in FortiWeb, FortiManager, and FortiClient

Fortinet has rolled out fixes for a batch of authentication-related vulnerabilities across its FortiWeb, FortiManager, and FortiClient product lines, urging administrators to patch quickly given the sensitivity of the affected systems. The most severe of the bunch, tracked as CVE-2026-26035, sits in FortiWeb’s login mechanism and carries a CVSS score in the 8. 8-to-9. 8 range depending on the source, reflecting just how easy it would be to abuse in the wrong configuration. According to Fortinet’s advisory, the flaw is an improper authentication issue (CWE-287) that surfaces when a FortiWeb administrator account is configured for Remote RADIUS Type authentication with the “wildcard” setting turned on.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek .

·SecurityWeek
Read →
Breaches & Ransomware
Emerging1 src

Gunra ransomware hackers exploit Fortinet flaws to breach critical infrastructure - Cybernews

Gunra ransomware hackers exploit Fortinet flaws to breach critical infrastructure Cybernews

·Cybernews
Read →
Vulnerabilities & Patches
Emerging1 src

Fortinet security advisory (AV26-812)

Serial number: AV26-812 Date: August 12, 2026 As of August 12, 2026, Fortinet is affected by a vulnerability in the following products: • FortiClientWindows • Prior to or equal to 7.2.11 • Prior to or equal to 7.4.3 • FortiManager • Prior to or equal to 7.61 • Prior to or equal to 7.4.5 • Prior to or equal to 7.2.9 • FortiManager Cloud • Prior to or equal to 7.61 • Prior to or equal to 7.4.5 • Prior to or equal to 7.2.9 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • PSIRT • FortiGuard Labs • PSIRT • FortiGuard Labs (1) • Fortinet PSIRT Advisories Fortinet security advisory (AV26-812) - Canadian Centre for Cyber Security

·Malware.news
Read →
Breaches & Ransomware
Emerging1 src

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

·Infosecurity Magazine
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-70465 - Fortinet FortiClient Buffer Overflow Vulnerability

CVE ID : CVE-2026-70465 Published : Aug. 12, 2026, 12:19 p. m. • 44 minutes ago Description : A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7. 4. 0 through 7. 4. 3, FortiClientWindows 7. 2. 0 through 7. 2. 11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets. Severity: 8.1 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

·CVEFeed
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-70468 - Fortinet FortiManager Authentication Bypass Vulnerability

CVE ID : CVE-2026-70468 Published : Aug. 12, 2026, 12:19 p. m. • 45 minutes ago Description : A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7. 6. 1, FortiManager 7. 4. 3 through 7. 4. 5, FortiManager 7. 2. 5 through 7. 2. 9, FortiManager Cloud 7. 6. 1, FortiManager Cloud 7. 4. 3 through 7. 4. 5, FortiManager Cloud 7. 2. 5 through 7. 2. 9 may allow attacker to improper access control via Severity: 7.3 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

·CVEFeed
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-26035 - Fortinet FortiWeb Improper Authentication Vulnerability

CVE ID : CVE-2026-26035 Published : Aug. 12, 2026, 12:19 p. m. • 45 minutes ago Description : An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8. 0. 0 through 8. 0. 2, FortiWeb 7. 6. 0 through 7. 6. 6, FortiWeb 7. 4. 0 through 7. 4. 11, FortiWeb 7. 2. 0 through 7. 2. 12, FortiWeb 7. 0. 0 through 7. 0. 12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password Severity: 8.8 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

·CVEFeed
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-70466 - Fortinet FortiWeb Improper Access Control

CVE ID : CVE-2026-70466 Published : Aug. 12, 2026, 12:19 p. m. • 45 minutes ago Description : A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8. 0. 0 through 8. 0. 2, FortiWeb 7. 6. 0 through 7. 6. 5, FortiWeb 7. 4 all versions, FortiWeb 7. 2 all versions, FortiWeb 7. 0 all versions may allow attacker to improper access control via Severity: 4.8 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

·CVEFeed
Read →
Vulnerabilities & Patches
Emerging1 src

Siemens RUGGEDCOM APE1808

View CSAF Summary Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures. The following versions of Siemens RUGGEDCOM APE1808 are affected: • RUGGEDCOM APE1808 vers:all/* (CVE-2026-23573, CVE-2026-59839) CVSS Vendor Equipment

·CISA Alerts
Read →
Breaches & Ransomware
Emerging1 src

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA - Dark Reading

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA Dark Reading

·Dark Reading
Read →
Breaches & Ransomware
Emerging1 src

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

·Dark Reading
Read →
Breaches & Ransomware
Emerging1 src

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Cybersecurity and intelligence agencies from South Korea and the U. S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of

·The Hacker News
Read →
Breaches & Ransomware
Emerging1 src

Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data

A joint cybersecurity advisory from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U. S. Secret Service, and South Korea’s National Police Agency has exposed a dangerous new wave of attacks by the Gunra ransomware group , which is actively exploiting known Fortinet VPN vulnerabilities to bypass multi-factor authentication and exfiltrate sensitive enterprise data before locking down victim networks. Gunra first surfaced in April 2025 as a double-extortion ransomware strain believed to be built on leaked Conti source code. By early 2026, the group had matured into a full ransomware-as-a-service operation, offering affiliates a management panel, a configurable ransomware builder, and cross-platform locker payloads through dark web forums.

·Cyber Security News
Read →