home.social

#fortimanager — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fortimanager, aggregated by home.social.

fetched live
  1. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

  2. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

    #Cybersecurity #Fortinet #BruteForce #CyberAttack #FortiOS #FortiManager

  3. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

    #Cybersecurity #Fortinet #BruteForce #CyberAttack #FortiOS #FortiManager

  4. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

    #Cybersecurity #Fortinet #BruteForce #CyberAttack #FortiOS #FortiManager

  5. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

    #Cybersecurity #Fortinet #BruteForce #CyberAttack #FortiOS #FortiManager

  6. #BSI WID-SEC-2025-1018: [NEU] [niedrig] #Fortinet #FortiManager: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen

    Ein lokaler Angreifer kann eine Schwachstelle in Fortinet FortiManager ausnutzen, um Sicherheitsvorkehrungen zu umgehen.

    wid.cert-bund.de/portal/wid/se

  7. #BSI WID-SEC-2025-1018: [NEU] [niedrig] #Fortinet #FortiManager: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen

    Ein lokaler Angreifer kann eine Schwachstelle in Fortinet FortiManager ausnutzen, um Sicherheitsvorkehrungen zu umgehen.

    wid.cert-bund.de/portal/wid/se

  8. #BSI WID-SEC-2025-0340: [NEU] [mittel] #Fortinet #FortiAnalyzer #und #FortiManager: Mehrere Schwachstellen

    Ein lokaler Angreifer kann mehrere Schwachstellen in Fortinet FortiAnalyzer und Fortinet FortiManager ausnutzen, um Dateien zu manipulieren und vertrauliche Informationen preiszugeben.

    wid.cert-bund.de/portal/wid/se

  9. #BSI WID-SEC-2025-0340: [NEU] [mittel] #Fortinet #FortiAnalyzer #und #FortiManager: Mehrere Schwachstellen

    Ein lokaler Angreifer kann mehrere Schwachstellen in Fortinet FortiAnalyzer und Fortinet FortiManager ausnutzen, um Dateien zu manipulieren und vertrauliche Informationen preiszugeben.

    wid.cert-bund.de/portal/wid/se

  10. #BSI WID-SEC-2025-0344: [NEU] [niedrig] #Fortinet #FortiManager: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen

    Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Fortinet FortiManager ausnutzen, um Sicherheitsvorkehrungen zu umgehen.

    wid.cert-bund.de/portal/wid/se

  11. #BSI WID-SEC-2025-0344: [NEU] [niedrig] #Fortinet #FortiManager: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen

    Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Fortinet FortiManager ausnutzen, um Sicherheitsvorkehrungen zu umgehen.

    wid.cert-bund.de/portal/wid/se

  12. Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager CVE-2024-47575

    "The low complexity of these #vulnerabilities brings into question the overall quality of the #FortiManager codebase...
    As far as we can make out, Fortinet just patched a chunk of irrelevant (dead?) code and left the actual #vulnerability alone, wide open for attackers."
    labs.watchtowr.com/hop-skip-fo

  13. Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager CVE-2024-47575

    "The low complexity of these #vulnerabilities brings into question the overall quality of the #FortiManager codebase...
    As far as we can make out, Fortinet just patched a chunk of irrelevant (dead?) code and left the actual #vulnerability alone, wide open for attackers."
    labs.watchtowr.com/hop-skip-fo

  14. Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager CVE-2024-47575

    "The low complexity of these #vulnerabilities brings into question the overall quality of the #FortiManager codebase...
    As far as we can make out, Fortinet just patched a chunk of irrelevant (dead?) code and left the actual #vulnerability alone, wide open for attackers."
    labs.watchtowr.com/hop-skip-fo

  15. Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager CVE-2024-47575

    "The low complexity of these #vulnerabilities brings into question the overall quality of the #FortiManager codebase...
    As far as we can make out, Fortinet just patched a chunk of irrelevant (dead?) code and left the actual #vulnerability alone, wide open for attackers."
    labs.watchtowr.com/hop-skip-fo

  16. Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager CVE-2024-47575

    "The low complexity of these #vulnerabilities brings into question the overall quality of the #FortiManager codebase...
    As far as we can make out, Fortinet just patched a chunk of irrelevant (dead?) code and left the actual #vulnerability alone, wide open for attackers."
    labs.watchtowr.com/hop-skip-fo

  17. Urgh.. why is the #FortiManager so crappy a lot of the time? #Fortinet :blobcatgooglynotlikethis:

  18. Urgh.. why is the #FortiManager so crappy a lot of the time? #Fortinet :blobcatgooglynotlikethis:

  19. ...et ce n'est pas fini!

    watchTowr fait le "teasing" sur le bad site de leur prochaine publication en conseillant carrément au détenteurs de Foritmanager exposé: "S'il vous plaît, retirez le d'Internet *même s'il est entièrement corrigé"

    Le correctif pour la vulnérabilité « FortiJump » dans la plateforme de gestion FortiManager de Fortinet pourrait ainsi ne pas avoir complètement résolu le problème. Malgré une mise à jour récente, des preuves montrent que la vulnérabilité CVE-2024-47575 est encore exploitable, ce qui expose potentiellement 62 000 instances de FortiManager connectées à Internet selon Cyble threat intelligence.
    ⬇️
    "FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch
    The FortiJump vulnerability in Fortinet FortiManager may not have been completely fixed by last month's patch. Users are urged to apply mitigations."
    👇
    thecyberexpress.com/fortimanag

    #CyberVeille
    #CVE_2024_47575
    #Fortinet #FortiJump #Fortimanager

  20. ...et ce n'est pas fini!

    watchTowr fait le "teasing" sur le bad site de leur prochaine publication en conseillant carrément au détenteurs de Foritmanager exposé: "S'il vous plaît, retirez le d'Internet *même s'il est entièrement corrigé"

    Le correctif pour la vulnérabilité « FortiJump » dans la plateforme de gestion FortiManager de Fortinet pourrait ainsi ne pas avoir complètement résolu le problème. Malgré une mise à jour récente, des preuves montrent que la vulnérabilité CVE-2024-47575 est encore exploitable, ce qui expose potentiellement 62 000 instances de FortiManager connectées à Internet selon Cyble threat intelligence.
    ⬇️
    "FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch
    The FortiJump vulnerability in Fortinet FortiManager may not have been completely fixed by last month's patch. Users are urged to apply mitigations."
    👇
    thecyberexpress.com/fortimanag

    #CyberVeille
    #CVE_2024_47575
    #Fortinet #FortiJump #Fortimanager

  21. ...et ce n'est pas fini!

    watchTowr fait le "teasing" sur le bad site de leur prochaine publication en conseillant carrément au détenteurs de Foritmanager exposé: "S'il vous plaît, retirez le d'Internet *même s'il est entièrement corrigé"

    Le correctif pour la vulnérabilité « FortiJump » dans la plateforme de gestion FortiManager de Fortinet pourrait ainsi ne pas avoir complètement résolu le problème. Malgré une mise à jour récente, des preuves montrent que la vulnérabilité CVE-2024-47575 est encore exploitable, ce qui expose potentiellement 62 000 instances de FortiManager connectées à Internet selon Cyble threat intelligence.
    ⬇️
    "FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch
    The FortiJump vulnerability in Fortinet FortiManager may not have been completely fixed by last month's patch. Users are urged to apply mitigations."
    👇
    thecyberexpress.com/fortimanag

    #CyberVeille
    #CVE_2024_47575
    #Fortinet #FortiJump #Fortimanager

  22. ...et ce n'est pas fini!

    watchTowr fait le "teasing" sur le bad site de leur prochaine publication en conseillant carrément au détenteurs de Foritmanager exposé: "S'il vous plaît, retirez le d'Internet *même s'il est entièrement corrigé"

    Le correctif pour la vulnérabilité « FortiJump » dans la plateforme de gestion FortiManager de Fortinet pourrait ainsi ne pas avoir complètement résolu le problème. Malgré une mise à jour récente, des preuves montrent que la vulnérabilité CVE-2024-47575 est encore exploitable, ce qui expose potentiellement 62 000 instances de FortiManager connectées à Internet selon Cyble threat intelligence.
    ⬇️
    "FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch
    The FortiJump vulnerability in Fortinet FortiManager may not have been completely fixed by last month's patch. Users are urged to apply mitigations."
    👇
    thecyberexpress.com/fortimanag

    #CyberVeille
    #CVE_2024_47575
    #Fortinet #FortiJump #Fortimanager

  23. 🚨CERT ALERT: FortiManager critical 0-day vulnerability exploited in the wild.

    It's been discussed off the record since the time of release earlier last week. 🤫

    The threat level of this advisory is thus considered very high (5/5, maximum severity level).📈🚨

    👉🤓Read Orange CyberDefense’s detailed World Watch Advisory to learn more: ow.ly/Wai430sHtfk

    #fortimanager
    #vulnerabilitymanagement #cybersecurity

  24. 🚨CERT ALERT: FortiManager critical 0-day vulnerability exploited in the wild.

    It's been discussed off the record since the time of release earlier last week. 🤫

    The threat level of this advisory is thus considered very high (5/5, maximum severity level).📈🚨

    👉🤓Read Orange CyberDefense’s detailed World Watch Advisory to learn more: ow.ly/Wai430sHtfk

    #fortimanager
    #vulnerabilitymanagement #cybersecurity

  25. 🚨CERT ALERT: FortiManager critical 0-day vulnerability exploited in the wild.

    It's been discussed off the record since the time of release earlier last week. 🤫

    The threat level of this advisory is thus considered very high (5/5, maximum severity level).📈🚨

    👉🤓Read Orange CyberDefense’s detailed World Watch Advisory to learn more: ow.ly/Wai430sHtfk

    #fortimanager
    #vulnerabilitymanagement #cybersecurity

  26. ❗️ #CERTWarnung ❗️
    In #FortiManager von Fortinet wurde eine Zero-Day #Schwachstelle geschlossen, die seit Juni ausgenutzt wird. Eine Kompromittierung ist zu prüfen. Kunden sollten unverzüglich ihre Geräte absichern. #PatchNow
    bsi.bund.de/SharedDocs/Cybersi

  27. ❗️ #CERTWarnung ❗️
    In #FortiManager von Fortinet wurde eine Zero-Day #Schwachstelle geschlossen, die seit Juni ausgenutzt wird. Eine Kompromittierung ist zu prüfen. Kunden sollten unverzüglich ihre Geräte absichern. #PatchNow
    bsi.bund.de/SharedDocs/Cybersi

  28. ❗️ #CERTWarnung ❗️
    In #FortiManager von Fortinet wurde eine Zero-Day #Schwachstelle geschlossen, die seit Juni ausgenutzt wird. Eine Kompromittierung ist zu prüfen. Kunden sollten unverzüglich ihre Geräte absichern. #PatchNow
    bsi.bund.de/SharedDocs/Cybersi

  29. ❗️ #CERTWarnung ❗️
    In #FortiManager von Fortinet wurde eine Zero-Day #Schwachstelle geschlossen, die seit Juni ausgenutzt wird. Eine Kompromittierung ist zu prüfen. Kunden sollten unverzüglich ihre Geräte absichern. #PatchNow
    bsi.bund.de/SharedDocs/Cybersi

  30. ❗️ #CERTWarnung ❗️
    In #FortiManager von Fortinet wurde eine Zero-Day #Schwachstelle geschlossen, die seit Juni ausgenutzt wird. Eine Kompromittierung ist zu prüfen. Kunden sollten unverzüglich ihre Geräte absichern. #PatchNow
    bsi.bund.de/SharedDocs/Cybersi

  31. fortiguard.com/psirt/FG-IR-24-

    „A missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.“

    Patch & establish micro-segmentation (only dedicated sources should be able to access FortiManager (and everything else); Use e.g. private-vlans & tighten your acls/firewall-policies)

    #infosec #fortinet #fortimanager

  32. fortiguard.com/psirt/FG-IR-24-

    „A missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.“

    Patch & establish micro-segmentation (only dedicated sources should be able to access FortiManager (and everything else); Use e.g. private-vlans & tighten your acls/firewall-policies)

    #infosec #fortinet #fortimanager