⚠️ Falsa patch di FortiClient EMS in circolazione: invece di proteggere, ruba dati dai browser. Aggiornate solo da fonti ufficiali. #CyberSecurity #FortiClient
🔗 https://www.tomshw.it/hardware/forticlient-ems-falsa-patch-ruba-dati-browser
Live and recent posts from across the Fediverse tagged #forticlient, aggregated by home.social.
⚠️ Falsa patch di FortiClient EMS in circolazione: invece di proteggere, ruba dati dai browser. Aggiornate solo da fonti ufficiali. #CyberSecurity #FortiClient
🔗 https://www.tomshw.it/hardware/forticlient-ems-falsa-patch-ruba-dati-browser
Hackers Exploit FortiClient Flaw to Deliver Infostealer Malware
Hackers are exploiting a vulnerability in FortiClient Enterprise Management Server to deliver infostealer malware, cleverly disguising the payload as a legitimate Fortinet endpoint update. This sneaky tactic uses FortiClient-managed VPN scripting workflows to execute the malicious code, putting security teams on high alert.
#Forticlient #Cve202635616 #InfostealerMalware #Exploit #ArbitraryCodeExecution
caro cliente italiano, se sai che io vivo in Svizzera da 20 anni (e lo sai) e hai bisogno che io mi connetta in vpn, per quale motivo mi dai un account vpn geograficamente limitato alla sola italia?
oltretutto con un client vpn a cui non piace il doppio passaggio (vpn su italia ➡️ vpn su cliente) (si, #forticlient, ce l'ho con te)
FortiClient EMS: Tausende Instanzen ungeschützt – aktive Angriffe über zwei RCE-Lücken
Die geografische Verteilung ist weit gestreut – USA und Deutschland weisen die höchste Konzentration auf
https://www.europesays.com/at/57196/ FortiClient EMS: Kritische Sicherheitslücke gefährdet Unternehmensdaten #Angreifern #AT #Austria #Authentifizierung #EMS #Endpoint #FortiClient #Kritische #Management #Österreich #Science #Science&Technology #Server #Sicherheitslücke #Technik #Technology #Unternehmensdaten #Wissenschaft #Wissenschaft&Technik
Schadcode-Lücke in #FortiClient EMS kann PCs kompromittieren | Security https://www.heise.de/news/Schadcode-kann-durch-FortiClient-EMS-Schwachstelle-schluepfen-11170228.html #Patchday
#Forticlient steht stellvertretend dafür da, was unter #Linux auf dem Desktop schief läuft
If you're using forticlient on linux, don't upgrade: the latest version drops SSLVPN.
I had to downgrade with a .deb from https://www.fortinet.com/support/product-downloads (after an "apt upgrade" on Debian).
Instale #forticlient sobre ubuntu 24.04 y salio tutorial (o ayuda memoria) para aquel que lo necesite.... simplon
https://luiszambrana.ar/instalar-forticlient-sobre-ubuntu-24-04/
#BSI WID-SEC-2025-1021: [NEU] [mittel] #Fortinet #FortiClient #Mac, #Windows, #EMS #und #FortiVoice: Mehrere Schwachstellen
Ein lokaler Angreifer kann mehrere Schwachstellen in Fortinet FortiClient und Fortinet FortiVoice ausnutzen, um beliebigen Code auszuführen, erhöhte Rechte zu erlangen, Daten zu manipulieren und vertrauliche Informationen preiszugeben.
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1021
Kann mich jemand unterstützen bei der Installation von #Fortigate #FortiClient #SSLVPN unter #Ubuntu 24 LTS. Der Client läuft, die Config ist auch klar, aber die einzige Meldung die ich beim connecten kriege ist "Login canceled".
#BSI WID-SEC-2025-0346: [NEU] [mittel] #Fortinet #FortiClient: Mehrere Schwachstellen
Ein lokaler Angreifer kann mehrere Schwachstellen in Fortinet FortiClient ausnutzen, um seine Privilegien zu erhöhen oder Sicherheitsmaßnahmen zu umgehen.
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0346
Heads up for anyone running FortiClient EMS 7.4.1 build 1872. I discovered that on November 14th the original bin installer had been replaced from the original bin file released on the November 1st.
There was no indication of this change or why this change was preformed.
After attempting to run security updates on a server using the bin file produced prior to the 14th, the package manager will auto uninstall and wipe the database of FortiClient EMS due to a dependency conflict with the PostgreSQL repository and FortiClient EMS not being protected as a manual install by default.
I upon testing, I discovered that this bin released on the 14th contain dependency list changes to reflect changes in the PostgreSQL repository. The original bin had strict version control that conflicted once the targeted version was removed from the third-party repository.
If you happen to be testing or running EMS and installed 7.4.1 build 1872 prior to November 14th, ensure you download and run the latest installer to prevent FortiClient EMS dependency conflicts prior to running any security updates. This is now being tracked under a customer support bulletin: CSB-250114-1 and it does appear that that bin files have been re-timestamped for January 14th 2025 but has a matching checksum to the November 14th file.
China-linked actor’s malware DeepData exploits FortiClient VPN zero-day – Source: securityaffairs.com https://ciso2ciso.com/china-linked-actors-malware-deepdata-exploits-forticlient-vpn-zero-day-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #FortiClientVPN #BrazenBamboo #BreakingNews #Intelligence #SecurityNews #FortiClient #hackingnews #DeepData
FortiClient VPN: запускаем скрипт, приложение или задачу после установки соединения
Привет, Я Саша Басун — системный администратор в «Петрович-Тех». Я уже писал на Хабре о пользовательских проблемах, и мне нравится автоматизировать такие задачи. В их решении есть своя магия. Статья будет о возможностях донастройки FortiClient VPN под пользователя. Эту информацию также можно вытащить из документации — но парадокс в том, что для её чтения нужен работающий VPN. Мы устанавливаем VPN-клиент в автоматическом режиме с нужными настройками. Через несколько секунд после подключения к серверу на рабочей станции должен запускаться определённый процесс. Ключевое слово — «должен»: он не всегда срабатывает как должно. Мне нужно было понять, в чём проблема, и найти решение для стабильного запуска.
https://habr.com/ru/companies/petrovich-tech/articles/858792/
While it creates the tunnel & declares the connection open, it doesn't finish the job, & the "bytes received" number stays at 0
This code sorts that out:
tunnel=`nmcli device status|grep fctvpn|gawk '{print $1}'`
sudo ip route add XX.XX.XX.XX/24 dev $tunnel
It probably needs multiple "ip route" commands to capture all of the relevant parts of the VPN, but this has the side-advantage of creating a split-tunnel setup, where only the IP addresses specified go through the VPN.
#BSI WID-SEC-2024-3450: [NEU] [hoch] #Fortinet #FortiClient für #macOS #und #Windows: Mehrere Schwachstellen
Ein lokaler Angreifer kann mehrere Schwachstellen in Fortinet FortiClient für macOS und Windows ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren oder seine Rechte zu erweitern.
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3450
No recordaba lo mierda que es configurar la VPN con #forticlient en un #linux
Todo el puto rato con un 'Failed to create SSL' y por lo que veo no soy el único, y todos los foros están plagados con lo mismo :(
Использование клиента Forti через подсистему Windows для Linux (WSL 2, WSLg)
TL;DR В статье рассказывается о доступе к внутрикорпоративным ресурсам через соединение Forti из подсистемы Windows для Linux (WSL).
Long shot but we have a #fortigate SSL VPN connection with specific DNS servers, we've updated them but the #forticlient isn't picking up the new IPs, any idea what might be up?