Professional Services Consultant at Check Point Software Technologies • #CyberSecurity • New England Patriots • #Pats4ever • EC Bad Nauheim • #KölnerHaie • Toots are mine #CheckPoint #firewall #networksecurity #accesscontrol #threatprevention not detection #proxmox #gitlab #python #ansible #automation #scripting #grafana #prometheus #opentelemetry
Daniel Kuhl ✌🏻☮️☕️
@daniel1820815@infosec.exchange
infosec.exchange
Hackers bypass patch using new FortiOS vulnerability
An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.
Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207440
Source: https://www.security-insider.de/fortios-ssl-vpn-cve-2025-68686-symlink-schutz-umgehung-a-ade1382fea7c3643c1d8af8d65355388/
#Fortinet #CVE
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
Discover how the FortiBleed malware campaign compromised thousands of FortiGate devices. Researchers have linked this massive operation to INC Ransom.
#FortiBleed #Malware #CyberSecurity #INCRansom #FortiGate
https://meterpreter.org/fortibleed-malware-campaign/?utm_source=mastodon&utm_medium=jetpack_social
k3ym𖺀
@k3ym0@infosec.exchange
[~]$ whoami principal killswitch engineer. beige-hat hacker. proud 1x engineer. cybernaut. blueteamer. privacy advocate. disciple of doctorow. reader of white papers. eff member. round-earther. cyber dark arts certified. professor emeritus of shitpostery and fellow at the institute of memetic research and development. i larp as a normie. (he/him) opinions expressed != employers
infosec.exchange
reminder that "fortibleed" is not a vuln. no CVE. no patch. nothing fucking "bled."
it's a russian-speaking crew firing 1.16 billion creds from old breaches and infostealer logs at every fortigate dumb enough to have its mgmt interface sitting on the public internet. ~50% of internet-facing boxes. half of you.
and before anyone cries "but my password was 28 characters with symbols": it didn't get cracked. it was already chilling in an infostealer dump in plaintext. great entropy, shame about the malware on your sales guy's laptop.
the -bleed suffix is marketing. the real CVE is CVE-2026-YOUREANIDIOT: "admin panel pointed at 0.0.0.0/0, password recycled from a 2022 breach, MFA considered but never enabled."
rotate the creds, yank the mgmt interface off the internet, force MFA, and maybe stop letting threat intel firms name your incidents like they're naming a fucking Marvel villain.
#infosec #fortinet #fortigate
You've seen all posts