#iinfosec — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iinfosec, aggregated by home.social.
-
CW: CSAM reporting requirements - not cyber security awareness month
Reminder. For #iinfosec cyber defenders, there’s only one thing you can find where you are required by law to notify the feds immediately, before even your employer.
US Code Title 18 s2251
https://www.law.cornell.edu/uscode/text/18/2251
Reporting requirements are s2258
https://www.law.cornell.edu/uscode/text/18/2258A
You report it to the National Center for Missing and Exploited Children here:
I am extremely fortunate I’ve never run into it, but I know #blueteam and #dfir people who have.
Always be the good guys. And leave these bad guys to the professionals. The amateur ‘catch a predator’ people have fubar’ed cases by not following legal procedure. Don’t give the villains an out.
-
This is far from the first vulnerability found in the FortiGate/FortiOS SSL VPN. I don't recommend it.
https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Fortios+VPN
#Fortinet #FortiGate #RCE #Exploit #Patching #VPN #Vulnerability #VulnerabilityManagement #IInfoSec