home.social

#fortijump — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fortijump, aggregated by home.social.

fetched live
  1. ...et ce n'est pas fini!

    watchTowr fait le "teasing" sur le bad site de leur prochaine publication en conseillant carrément au détenteurs de Foritmanager exposé: "S'il vous plaît, retirez le d'Internet *même s'il est entièrement corrigé"

    Le correctif pour la vulnérabilité « FortiJump » dans la plateforme de gestion FortiManager de Fortinet pourrait ainsi ne pas avoir complètement résolu le problème. Malgré une mise à jour récente, des preuves montrent que la vulnérabilité CVE-2024-47575 est encore exploitable, ce qui expose potentiellement 62 000 instances de FortiManager connectées à Internet selon Cyble threat intelligence.
    ⬇️
    "FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch
    The FortiJump vulnerability in Fortinet FortiManager may not have been completely fixed by last month's patch. Users are urged to apply mitigations."
    👇
    thecyberexpress.com/fortimanag

    #CyberVeille
    #CVE_2024_47575
    #Fortinet #FortiJump #Fortimanager

  2. Don’t worry everybody, #FortiJump is back for Christmas… this time set in space! The patch didn’t fix the variants.

  3. I think this got lost in the mix - the #FortiJump threat actress wasn’t just exploiting FortiManager.

    Both FortiGate (the firewall product) and FortiManager (the central manager product) use FGFM on port 541.

    The threat actress had different exploits for both products - the February FortiGate CVE and the new FortiManager CVE.

    One recommended mitigation in FortiManager is you lock FGFM to allowed IPs of your FortiGates. If you pop the FortiGate first you can reach the FortiManager by design.

  4. Ah, ein Fortinet Zero Day. Glücklicherweise liefern die Leute auch ihren eigenen Soundtrack mit #fortijump

    *düdü düd dü*

  5. FortiNet have now gone public about FortiJump, aka CVE-2024-47575 fortiguard.fortinet.com/psirt/

    Not in the advisory but exploitation stems to at least September, and it's being used to enter downstream networks.

    #FortiJump