Mallox Ransomware

FortiGuard Labs continue to see increase in Mallox ransomware related activities detecting Mallox ransomware on multiple hundred FortiGuard sensors. Ransomware infection may cause disruption, damage to daily operations, potential impact …

GeoServer RCE Attack

A remote code execution vulnerability within GeoServer is currently under active exploitation, with recent incidents targeting 40,000 sensors. This vulnerability is being exploited by the Earth Baxia APT group, as …

Russian Cyber Espionage Attack

FortiGuard Labs continues to observe attack attempts exploiting the vulnerabilities highlighted in the recent CISA advisory about Russian military cyber actors. These actors are targeting U.S. and global critical infrastructure …

Jenkins RCE Attack

Cyber threat actors are actively target Jenkins Arbitrary File Read vulnerability (CVE-2024-23897) in ransomware attacks. FortiGuard Labs continues to see active attack telemetry targeting the vulnerability.

Apache OFBiz RCE Attack

FortiGuard Labs continues to observe attack attempts targeting the recent Apache OFBiz vulnerabilities (CVE-2024-38856, CVE-2024-36104) that can be exploited by unauthorized threat actors through maliciously crafted requests, leading to the …

ServiceNow Remote Code Execution Attack

FortiGuard Labs continue to observe attack attempts targeting the recent ServiceNow Platform vulnerabilities (CVE-2024-4879, CVE-2024-5217, & CVE-2024-5178). When chained together, could lead to Remote Code Execution and potential data breaches …

PHP RCE Attack

FortiGuard Labs has observed increased exploitation attempts targeting the new PHP vulnerability on over 25,000 unique IPS devices. The TellYouThePass ransomware gang has been leveraging CVE-2024-4577, a remote code execution …

SolarWinds Orion Attack

SolarWinds [signed] software containing a planted vulnerability released in March 2020 as a regular (trusted) software patch. The backdoor was not discovered until the FireEye breach became public 9 months …