home.social

#fortios — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fortios, aggregated by home.social.

fetched live
  1. The Linux build's catastrophic cryptographic weakness notwithstanding, the Windows variant performed admirably. You had remediation options. You had patch notes. Patch Fortinet FortiOS and FortiProxy immediately.

    Reward: The court awards you a Complimentary Ransom Note, suitable for framing.

    #Ransomware #Fortinet #CyberSecurity #FortiOS #ThreatIntelligence #AchievementUnlocked (2/2)

  2. The Linux build's catastrophic cryptographic weakness notwithstanding, the Windows variant performed admirably. You had remediation options. You had patch notes. Patch Fortinet FortiOS and FortiProxy immediately.

    Reward: The court awards you a Complimentary Ransom Note, suitable for framing.

    #Ransomware #Fortinet #CyberSecurity #FortiOS #ThreatIntelligence #AchievementUnlocked (2/2)

  3. The Linux build's catastrophic cryptographic weakness notwithstanding, the Windows variant performed admirably. You had remediation options. You had patch notes. Patch Fortinet FortiOS and FortiProxy immediately.

    Reward: The court awards you a Complimentary Ransom Note, suitable for framing.

    #Ransomware #Fortinet #CyberSecurity #FortiOS #ThreatIntelligence #AchievementUnlocked (2/2)

  4. Hackers bypass patch using new FortiOS vulnerability

    An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.

    Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.

    euvd.enisa.europa.eu/vulnerabi

    Source: security-insider.de/fortios-ss

    #Fortinet #CVE

  5. Hackers bypass patch using new FortiOS vulnerability

    An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.

    Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.

    euvd.enisa.europa.eu/vulnerabi

    Source: security-insider.de/fortios-ss

    #Fortinet #CVE

  6. Hackers bypass patch using new FortiOS vulnerability

    An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.

    Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.

    euvd.enisa.europa.eu/vulnerabi

    Source: security-insider.de/fortios-ss

    #Fortinet #CVE

  7. Hackers bypass patch using new FortiOS vulnerability

    An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.

    Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.

    euvd.enisa.europa.eu/vulnerabi

    Source: security-insider.de/fortios-ss

    #Fortinet #CVE

  8. Hackers bypass patch using new FortiOS vulnerability

    An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.

    Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.

    euvd.enisa.europa.eu/vulnerabi

    Source: security-insider.de/fortios-ss

    #Fortinet #CVE

  9. An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS.

    KEV confirmed.

    #fortinet #kev #fortios #cybersecurity

    vulnerability.circl.lu/vuln/CV

  10. An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS.

    KEV confirmed.

    #fortinet #kev #fortios #cybersecurity

    vulnerability.circl.lu/vuln/CV

  11. An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS.

    KEV confirmed.

    #fortinet #kev #fortios #cybersecurity

    vulnerability.circl.lu/vuln/CV

  12. An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS.

    KEV confirmed.

    #fortinet #kev #fortios #cybersecurity

    vulnerability.circl.lu/vuln/CV

  13. An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS.

    KEV confirmed.

    #fortinet #kev #fortios #cybersecurity

    vulnerability.circl.lu/vuln/CV

  14. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  15. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  16. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  17. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  18. Si vous administrez des FortiGate/FortiOS : des admins signalent un contournement du patch de la vulnérabilité critique CVE-2025-59718 (FortiCloud SSO fortiguard.fortinet.com/psirt/ ) → compromission possible même sur des firewalls « patchés » (ex. 7.4.9/7.4.10).

    ( reddit.com/r/fortinet/comments )

    Préreq : “Allow administrative login using FortiCloud SSO” activé (souvent après enregistrement FortiCare).

    Mitigation : désactiver admin-forticloud-sso-login + restreindre l’accès admin + vérifier logs/nouveaux comptes.

    Chaîne d'exploitation: CVE-2025-59718 (+ CVE-2025-59719 côté FortiWeb) ➡️ envoi de messages SAML forgés ➡️ bypass de vérification de signature ➡️ accès admin non autorisé.

    [Références]
    "Fortinet admins report patched FortiGate firewalls getting hacked"
    👇
    bleepingcomputer.com/news/secu

    ( cyberveille.ch/posts/2026-01-2)

    💬
    ⬇️
    infosec.pub/post/40878137

    #CyberVeille #Fortinet #FortiGate #FortiOS #CVE_2025_59718

  19. Si vous administrez des FortiGate/FortiOS : des admins signalent un contournement du patch de la vulnérabilité critique CVE-2025-59718 (FortiCloud SSO fortiguard.fortinet.com/psirt/ ) → compromission possible même sur des firewalls « patchés » (ex. 7.4.9/7.4.10).

    ( reddit.com/r/fortinet/comments )

    Préreq : “Allow administrative login using FortiCloud SSO” activé (souvent après enregistrement FortiCare).

    Mitigation : désactiver admin-forticloud-sso-login + restreindre l’accès admin + vérifier logs/nouveaux comptes.

    Chaîne d'exploitation: CVE-2025-59718 (+ CVE-2025-59719 côté FortiWeb) ➡️ envoi de messages SAML forgés ➡️ bypass de vérification de signature ➡️ accès admin non autorisé.

    [Références]
    "Fortinet admins report patched FortiGate firewalls getting hacked"
    👇
    bleepingcomputer.com/news/secu

    ( cyberveille.ch/posts/2026-01-2)

    💬
    ⬇️
    infosec.pub/post/40878137

    #CyberVeille #Fortinet #FortiGate #FortiOS #CVE_2025_59718

  20. Si vous administrez des FortiGate/FortiOS : des admins signalent un contournement du patch de la vulnérabilité critique CVE-2025-59718 (FortiCloud SSO fortiguard.fortinet.com/psirt/ ) → compromission possible même sur des firewalls « patchés » (ex. 7.4.9/7.4.10).

    ( reddit.com/r/fortinet/comments )

    Préreq : “Allow administrative login using FortiCloud SSO” activé (souvent après enregistrement FortiCare).

    Mitigation : désactiver admin-forticloud-sso-login + restreindre l’accès admin + vérifier logs/nouveaux comptes.

    Chaîne d'exploitation: CVE-2025-59718 (+ CVE-2025-59719 côté FortiWeb) ➡️ envoi de messages SAML forgés ➡️ bypass de vérification de signature ➡️ accès admin non autorisé.

    [Références]
    "Fortinet admins report patched FortiGate firewalls getting hacked"
    👇
    bleepingcomputer.com/news/secu

    ( cyberveille.ch/posts/2026-01-2)

    💬
    ⬇️
    infosec.pub/post/40878137

    #CyberVeille #Fortinet #FortiGate #FortiOS #CVE_2025_59718

  21. Si vous administrez des FortiGate/FortiOS : des admins signalent un contournement du patch de la vulnérabilité critique CVE-2025-59718 (FortiCloud SSO fortiguard.fortinet.com/psirt/ ) → compromission possible même sur des firewalls « patchés » (ex. 7.4.9/7.4.10).

    ( reddit.com/r/fortinet/comments )

    Préreq : “Allow administrative login using FortiCloud SSO” activé (souvent après enregistrement FortiCare).

    Mitigation : désactiver admin-forticloud-sso-login + restreindre l’accès admin + vérifier logs/nouveaux comptes.

    Chaîne d'exploitation: CVE-2025-59718 (+ CVE-2025-59719 côté FortiWeb) ➡️ envoi de messages SAML forgés ➡️ bypass de vérification de signature ➡️ accès admin non autorisé.

    [Références]
    "Fortinet admins report patched FortiGate firewalls getting hacked"
    👇
    bleepingcomputer.com/news/secu

    ( cyberveille.ch/posts/2026-01-2)

    💬
    ⬇️
    infosec.pub/post/40878137

    #CyberVeille #Fortinet #FortiGate #FortiOS #CVE_2025_59718

  22. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

  23. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

    #Cybersecurity #Fortinet #BruteForce #CyberAttack #FortiOS #FortiManager

  24. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

    #Cybersecurity #Fortinet #BruteForce #CyberAttack #FortiOS #FortiManager

  25. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

    #Cybersecurity #Fortinet #BruteForce #CyberAttack #FortiOS #FortiManager

  26. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

    #Cybersecurity #Fortinet #BruteForce #CyberAttack #FortiOS #FortiManager

  27. Critical vulnerability allows attackers to bypass authentication on Fortinet devices. Is your network infrastructure at risk? Discover which versions are vulnerable and how to protect your systems immediately.

    #SecurityLand #CyberWatch #CyberSecurity #Fortinet #Vulnerability #FortiOS

    Read More: security.land/critical-fortine

  28. Critical vulnerability allows attackers to bypass authentication on Fortinet devices. Is your network infrastructure at risk? Discover which versions are vulnerable and how to protect your systems immediately.

    #SecurityLand #CyberWatch #CyberSecurity #Fortinet #Vulnerability #FortiOS

    Read More: security.land/critical-fortine

  29. #BSI WID-SEC-2025-1025: [NEU] [mittel] #Fortinet #FortiOS: Mehrere Schwachstellen ermöglicht Denial of Service

    Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Fortinet FortiOS ausnutzen, um einen Denial of Service Angriff durchzuführen.

    wid.cert-bund.de/portal/wid/se

  30. #BSI WID-SEC-2025-1025: [NEU] [mittel] #Fortinet #FortiOS: Mehrere Schwachstellen ermöglicht Denial of Service

    Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Fortinet FortiOS ausnutzen, um einen Denial of Service Angriff durchzuführen.

    wid.cert-bund.de/portal/wid/se

  31. #BSI WID-SEC-2025-1026: [NEU] [hoch] #Fortinet #FortiOS, #FortiProxy #und #FortiSwitch: Schwachstelle ermöglicht Privilegieneskalation

    Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Fortinet FortiOS, Fortinet FortiProxy und Fortinet FortiSwitch ausnutzen, um seine Privilegien zu erhöhen.

    wid.cert-bund.de/portal/wid/se

  32. #BSI WID-SEC-2025-1026: [NEU] [hoch] #Fortinet #FortiOS, #FortiProxy #und #FortiSwitch: Schwachstelle ermöglicht Privilegieneskalation

    Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Fortinet FortiOS, Fortinet FortiProxy und Fortinet FortiSwitch ausnutzen, um seine Privilegien zu erhöhen.

    wid.cert-bund.de/portal/wid/se

  33. CISA added two Known Exploited Vulnerabilities (KEV) to its catalog that pose a risk to federal enterprise. The flaws were in Fortinet's FortiOS and FortiProxy.

    Read TechNadu's report: technadu.com/cisa-warns-of-git

    #CISA #Vulnerability #Fortinet #GitHub #FortiProxy #FortiOS

  34. CISA added two Known Exploited Vulnerabilities (KEV) to its catalog that pose a risk to federal enterprise. The flaws were in Fortinet's FortiOS and FortiProxy.

    Read TechNadu's report: technadu.com/cisa-warns-of-git

    #CISA #Vulnerability #Fortinet #GitHub #FortiProxy #FortiOS