#fortinet

12 posts · Last used 7d

Back to Timeline
Daniel Kuhl ✌🏻☮️☕️ @daniel1820815@infosec.exchange · Aug 07, 2026
Hackers bypass patch using new FortiOS vulnerability An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise. Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk. https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207440 Source: https://www.security-insider.de/fortios-ssl-vpn-cve-2025-68686-symlink-schutz-umgehung-a-ade1382fea7c3643c1d8af8d65355388/ #Fortinet #CVE
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 27, 2026
CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now. #CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity https://securityonline.info/cisa-kev-arista-velocloud-fortios/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
AA @AAKL@infosec.exchange · Jul 27, 2026

CISA has added a vulnerability to the KEV catalogue.

0
0
0
ServeTheHome @sth@friendica.helvetet.eu · Jul 21, 2026
Fortinet is the latest Intel Foundry customer as the companies disclosed that the FortiSP6 will be a collaboration with Intel#Fortinet #Intel Intel Foundry Nabs A Custom ASIC Win with Fortinet
0
0
0
Michael I Ransier @thecybermind@infosec.exchange · Jul 20, 2026
⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. https://thecybermind.co/mxq2 #CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026
0
0
0
Michael I Ransier @thecybermind@infosec.exchange · Jul 20, 2026
⚠️ CRITICAL THREAT: CVE-2026-39808 in Fortinet FortiSandbox is being actively exploited. Attackers are leveraging OS command injection for remote code execution. Is your SOC ready? Get the forensic detection queries and hardening playbooks to lock down your perimeter. https://thecybermind.co/v66d #CyberSecurity #InfoSec #Fortinet
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 17, 2026
CISA KEV catalog adds three actively exploited flaws: FortiSandbox CVE-2026-25089, CVE-2026-39808, and SharePoint CVE-2026-58644. Patch by July 19. #CISA #KEV #Fortinet #FortiSandbox #SharePoint #CVE202658644 #ActivelyExploited #CyberSecurity https://securityonline.info/cisa-kev-fortisandbox-sharepoint/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 15, 2026
🚨 High-Severity FortiSandbox Flaw Disclosed CVE-2026-59835 (CVSS 7.7) allows unauthenticated attackers to access VNC servers used by FortiSandbox malware analysis VMs, potentially exposing malware samples, analysis sessions, screenshots, and security research activities. ✅ No authentication required ✅ Network exploitable ✅ Patch available If you're running FortiSandbox 5.0.x or 4.4.x, prioritize updates immediately. 🔗 Full technical breakdown: https://thecybersecguru.com/news/fortisandbox-cve-2026-59835-vnc-vulnerability/ #CVE2026-59835 #Fortinet #FortiSandbox #CyberSecurity #InfoSec #Vulnerability #ThreatIntel #BlueTeam #SOC #MalwareAnalysis #SecurityResearch #PatchNow #CVE #CyberThreats
0
0
0
k3ym𖺀 @k3ym0@infosec.exchange · Jun 18, 2026
reminder that "fortibleed" is not a vuln. no CVE. no patch. nothing fucking "bled." it's a russian-speaking crew firing 1.16 billion creds from old breaches and infostealer logs at every fortigate dumb enough to have its mgmt interface sitting on the public internet. ~50% of internet-facing boxes. half of you. and before anyone cries "but my password was 28 characters with symbols": it didn't get cracked. it was already chilling in an infostealer dump in plaintext. great entropy, shame about the malware on your sales guy's laptop. the -bleed suffix is marketing. the real CVE is CVE-2026-YOUREANIDIOT: "admin panel pointed at 0.0.0.0/0, password recycled from a 2022 breach, MFA considered but never enabled." rotate the creds, yank the mgmt interface off the internet, force MFA, and maybe stop letting threat intel firms name your incidents like they're naming a fucking Marvel villain. #infosec #fortinet #fortigate
29
2
19
Guia de TI @guiadeti@flipboard.social · Feb 23, 2026
0
0
0
C. @cazabon@mindly.social · Jan 28, 2026
Another #Fortinet critical security hole, so it must be a day that ends in "Y". #security #WeveHeardOfIt #bug #hole #SecurityHole
3
1
1

You've seen all posts