Citrix Bleed 2

FortiGuard Labs has observed a sharp increase in exploitation attempts targeting the ‚Citrix Bleed 2‘ vulnerability since July 28, 2025. Telemetry indicates activity has surged to over 6,000 detections across …

Microsoft SharePoint Zero-day Attack

FortiGuard Labs has detected and successfully blocked hundreds of exploitation attempts targeting a newly discovered zero-day vulnerability chain in on-premises Microsoft SharePoint servers. This active campaign is being exploited by …

SonicWall Secure Mobile Access Attack

A campaign targeting SonicWall SMA 100 series appliances is under active exploitation, leveraging both known and potential zero-day vulnerabilities to gain persistent access to enterprise networks. The attackers deploy a …

TBK DVRs Botnet Attack

Threat Actors are actively exploiting CVE-2024-3721, a command injection vulnerability in TBK DVR devices (Digital Video Recorders). This flaw allows unauthenticated remote code execution (RCE) via crafted HTTP requests to …

SimpleHelp Support Software Attack

FortiGuard Labs continues to observe ongoing attack attempts targeting SimpleHelp, a Remote Monitoring and Management (RMM) software, due to a critical unauthenticated path traversal vulnerability (CVE-2024-57727) affecting versions 5.5.7 and …

Earth Lamia APT Attack

The hacking group known as Earth Lamia has been targeting various sectors including finance, government, IT, logistics, retail, and education, shifting focus depending on the time period. The group is …

Langflow Unauth RCE Attack

FortiGuard Labs has observed a significant uptick in attacks targeting Langflow, leveraging a recently discovered authentication bypass vulnerability that allows unauthenticated remote attackers to fully compromise affected servers.