QuickFox Supply Chain Attack

FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily used by overseas Chinese users. Attackers tampered with official Windows installers to deploy …

WP2Shell RCE

FortiGuard Labs continues to detect exploitation attempts targeting the WP2Shell attack chain (CVE-2026-63030 and CVE-2026-60137), a critical unauthenticated remote code execution (RCE) vulnerability affecting WordPress Core. Telemetry collected over the …

Joomla SP Page Builder RCE

FortiGuard Labs continues to observe active exploitation of CVE-2026-48908, a critical unauthenticated remote code execution vulnerability affecting the JoomShaper SP Page Builder extension for Joomla. At the time of release, …

HTTP/2 Bomb Denial-of-Service Vulnerability

Security researchers have disclosed a new denial-of-service (DoS) attack technique dubbed HTTP/2 Bomb, tracked as CVE-2026-49975, that affects multiple major HTTP/2 server implementations. Unlike traditional volumetric DDoS attacks, HTTP/2 Bomb …

Iran-linked Cyber Attacks

This report provides an overview of ongoing Iran-linked cyber operations, highlighting activity attributed to state-aligned proxies and hacktivist groups. The vulnerabilities listed are suspected to be exploited by actors associated …

Interlock Ransomware Attack

An active Interlock ransomware campaign is exploiting a critical vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC), enabling unauthenticated remote code execution as root. The campaign combines edge-device exploitation, …