SolarWinds Orion Attack
SolarWinds [signed] software containing a planted vulnerability released in March 2020 as a regular (trusted) software patch. The backdoor was not discovered until the FireEye breach became public 9 months …
Fortinet Blog
SolarWinds [signed] software containing a planted vulnerability released in March 2020 as a regular (trusted) software patch. The backdoor was not discovered until the FireEye breach became public 9 months …
Known exploited vulnerabilities in the Oracle WebLogic Server. The vulnerabilities allows an unauthenticated attacker with network to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized …
Multiple D-link device vulnerabilities are being actively targeted. Many of the Routers and NAS device are end-of-life D-Link devices that does not have any patches available.
APT Actors are actively exploiting Zoho ManageEngine ServiceDesk Plus which is an IT help desk software with asset management. The exploit is tracked via CVE-2021-44077 and rated critical due to …
FortiGuard labs observed a critical level of attack attempts in the wild targeting a 2 year old vulnerability found on C-DATA Web Management Systems.
FortiGuard Labs continue to observe detections in the wild related to the Akira ransomware group. According to the new report by CISA it has targeted over 250 organizations since the …
The on-going attack on PAN-OS GlobalProtect devices identified as CVE-2024-3400 allows a malicious actor to remotely exploit an unauthenticated OS Command Injection vulnerability. Once established, the attacker can further collect …
FortiGuard Labs continues to see targeted attacks affecting a vulnerability, identified as CVE-2021-36380, that enables a malicious actor to establish an interactive conduit, gaining command over the targeted system and …
