CVE-2023-48788
published 2024-03-12CVE-2023-48788: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2024-04-15
Exploited in the wild
EPSS
97.59%
99.9th percentile
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient_enterprise_management_server | >= 7.0.1 < 7.0.11 | 7.0.11 |
| fortinet | forticlient_enterprise_management_server | >= 7.2.0 < 7.2.3 | 7.2.3 |
| fortinet | forticlientems | — | — |
| fortinet | forticlientems | 7.0.1 – 7.0.10 | — |
| fortinet | forticlientems | 7.2.0 – 7.2.2 | — |
| fortinet | forticliententerprisemanagementserver | — | — |
| fortinet | fortinet | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandRemove-Item (Get-PSReadlineOption).HistorySavePath
commandmmc.exe compmgmt.msc /computer:{hostname/ip}
domainfilemail.com
- →Monitor the FortiClient EMS SQL Server error log at C:\Program Files\Microsoft SQL Server\MSSQL14.FCEMS\MSSQL\Log\ERRORLOG.X for malformed or unexpected SQL queries indicating injection attempts. ↗
- →Alert on sqlservr.exe (MSSQL14.FCEMS instance) spawning cmd.exe or powershell.exe child processes, as this is the direct exploitation chain for CVE-2023-48788. ↗
- →Hunt for curl or certutil downloading files to C:\update.exe followed by execution, as this is the post-exploitation ScreenConnect installer staging pattern. ↗
- →Monitor for outbound PowerShell Invoke-WebRequest (iwr) POST requests to webhook.site, used by the threat actor to beacon from vulnerable FortiClient EMS targets during scanning. ↗
- →Detect presence of HRSword.exe (Huorong Internet Security) on non-Huorong-licensed endpoints, as it was used by attackers for defense evasion post-exploitation. ↗
- →Review AnyDesk trace logs at C:\ProgramData\AnyDesk\ad_svc.trace for attacker-controlled remote IP addresses following FortiClient EMS compromise. ↗
- →Alert on access to administrative shares (C$, IPC$, ADMIN$) and registry hives (HKLM\SAM, HKLM\SECURITY) via Remote Registry service from internal IPs following FortiClient EMS exposure. ↗
- →Track repeated use of the same usernames, passwords, and source endpoint names (e.g., '0DAY-PROJECT', 'kali') across incidents for high-fidelity detection of threat actor reuse patterns linked to CVE-2023-48788 exploitation. ↗
- →Detect SimpleHelp RMM installation following FortiClient EMS exploitation, as threat actors consistently deployed it for persistence after initial access via CVE-2023-48788. ↗
- ·The FortiClient EMS ems.log and sql_trace.log paths are key forensic artifacts but may not be present on all deployments; sql_trace.log is conditional on SQL tracing being enabled. ↗
- ·The webhook.site token in observed scanning activity was partially redacted; the specific token value cannot be used as a static IOC, but the pattern of POST beaconing to webhook.site from FortiClient EMS servers is actionable. ↗
- ·The ScreenConnect installer URL uses a 'Guest' trial license parameter (y=Guest); blocking this specific URL pattern may not catch variants using paid or differently parameterized ScreenConnect deployments. ↗
- ·The attacker IP identified via AnyDesk logs was located in the Russian region and associated with Cobalt Strike abuse, but the specific IP was not fully disclosed in the report. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fv47-jg3j-5qf6: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7
ghsa_unreviewed·2024-03-12
CVE-2023-48788 [CRITICAL] CWE-89 GHSA-fv47-jg3j-5qf6: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
VulnCheck
Fortinet FortiClient EMS SQL Injection Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-48788 [CRITICAL] CWE-89 Fortinet FortiClient EMS SQL Injection Vulnerability
Fortinet FortiClient EMS SQL Injection Vulnerability
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
Affected: Fortinet FortiClient EMS
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://fortiguard.fortinet.com/psirt/FG-IR-24-007; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://redcanary.com/blog/cve-2023-48788/; https://www.forescout.com/blog/connectfun-new-exploit-campaign-in-the-wild-targets-media-company/; https://www.forescout.com/resources/connectfun-threat-briefing/; https:
CISA
Fortinet FortiClient EMS SQL Injection Vulnerability
cisa·2024-03-25·CVSS 9.8
CVE-2023-48788 [CRITICAL] CWE-89 Fortinet FortiClient EMS SQL Injection Vulnerability
Vulnerability: Fortinet FortiClient EMS SQL Injection Vulnerability
Affected: Fortinet FortiClient EMS
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.fortiguard.com/psirt/FG-IR-24-007; https://nvd.nist.gov/vuln/detail/CVE-2023-48788
Remediation Due Date: 2024-04-15
Fortinet
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio...
vendor_fortinet·2024-03-12·CVSS 9.8
CVE-2023-48788 [CRITICAL] CWE-89 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio...
FG-IR-24-007: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio...
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
CVEs: CVE-2023-48788
CWEs: CWE-89
CVSS: 9.8 (critical)
Affected products: FortiClientEMS, FortiCliententerprisemanagementserver, Fortinet
Suricata
ET EXPLOIT Fortinet FortiClient EMS SQL Injection (CVE-2023-48788)
suricata·2024-12-19·CVSS 9.8
CVE-2023-48788 [CRITICAL] ET EXPLOIT Fortinet FortiClient EMS SQL Injection (CVE-2023-48788)
ET EXPLOIT Fortinet FortiClient EMS SQL Injection (CVE-2023-48788)
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Fortinet FortiClient EMS SQL Injection (CVE-2023-48788)"; flow:established,to_server; content:"MSG_HEADER|3a 20|FCTUID|3d|"; fast_pattern; startswith; pcre:"/^[^\x0a]*?[\x27\x22\x3b\x2d\x5c\x2a\x2f]/R"; reference:url,www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive; reference:cve,2023-48788; classtype:attempted-admin; sid:2058432; rev:1; metadata:affected_product FortiClient_EMS, attack_target Server, tls_state TLSDecrypt, created_at 2024_12_19, cve CVE_2023_48788, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV,
Metasploit
FortiNet FortiClient Endpoint Management Server FCTID SQLi to RCE
metasploit
FortiNet FortiClient Endpoint Management Server FCTID SQLi to RCE
FortiNet FortiClient Endpoint Management Server FCTID SQLi to RCE
An SQLi injection vulnerability exists in FortiNet FortiClient EMS (Endpoint Management Server). FortiClient EMS serves as an endpoint management solution tailored for enterprises, offering a centralized platform for overseeing enrolled endpoints. The SQLi is vulnerability is due to user controller strings which can be sent directly into database queries. FcmDaemon.exe is the main service responsible for communicating with enrolled clients. By default it listens on port 8013 and communicates with FCTDas.exe which is responsible for translating requests and sending them to the database. In the message header of a specific request sent between the two services, the FCTUID parameter is vulnerable SQLi. The SQLi can used to ena
Nuclei
Fortinet Forticlient Endpoint Management Server - SQL Injection
nuclei·CVSS 9.8
CVE-2023-48788 [CRITICAL] Fortinet Forticlient Endpoint Management Server - SQL Injection
Fortinet Forticlient Endpoint Management Server - SQL Injection
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
Template:
id: CVE-2023-48788
info:
name: Fortinet Forticlient Endpoint Management Server - SQL Injection
author: James Horseman,ItshMoh
severity: critical
description: |
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
impact: |
Unauthenticated at
Wiz
Opening the Black Box: Agentless Threat Detection for Virtual Appliances
blogs_wiz·2026-07-22
CVE-2026-24858 Opening the Black Box: Agentless Threat Detection for Virtual Appliances
## Introduction
Virtual appliances are common in the cloud, 51.9% of cloud environments have at least one virtual appliance and 46.4% of those have exposed at least one virtual appliance to the Internet. They are often Internet-facing and commonly act as key network and security components, such as firewalls, gateways, WAFs, proxies, and SSL VPNs. These appliances also frequently operate with elevated privileges; for example, 65% of organizations using Aviatrix have instances with high control plane privileges. However, despite their critical role, these appliances often operate as “black boxes”. They typically do not support traditional security tooling such as EDR or antivirus agents, creating a significant visibility gap for security teams. The toxic combination of exposure and privile
Hackernews
INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
blogs_hackernews·2026-06-18
CVE-2023-3519 INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims since August 2023.
"The disruption of LockBit and the shutdown of BlackCat created opportunities for INC to expand as affiliates migrated to alternative ransomware operations," Acronis researcher Darrel Virtusio said . "United States organizations account for more than 65% of listed victims, with legal services, manufacturing, construction, te
Tenable
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends
blogs_tenable·2025-04-23
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
Kaspersky Incident Response analyst report for 2024
blogs_securelist·2025-03-12
Kaspersky Incident Response analyst report for 2024
Table of Contents
- Regions and industries of incident response requests
- Key 2024 trends and statistics
- Recommendations for preventing incidents
Authors
- Kaspersky GERT
- Kaspersky Security Services
Kaspersky provides rapid and fully informed incident response services to organizations, ensuring impact analysis and effective remediation. Our annual report shares anonymized data about the investigations carried out by the Kaspersky Global Emergency Response Team (GERT), as well as statistics and trends in targeted attacks, ransomware and adversaries’ tools that our experts observed throughout the year in real-life incidents that required both comprehensive IR unit support and consulting services aimed at assisting organizations’ in-house expert teams.
Download the full version of
Securelist
Incident response analyst report 2024
blogs_securelist·2025-03-12
Incident response analyst report 2024
Table of Contents
Regions and industries of incident response requests
Key 2024 trends and statistics
Recommendations for preventing incidents
Authors
Kaspersky GERT
Kaspersky Security Services
Kaspersky provides rapid and fully informed incident response services to organizations, ensuring impact analysis and effective remediation. Our annual report shares anonymized data about the investigations carried out by the Kaspersky Global Emergency Response Team (GERT), as well as statistics and trends in targeted attacks, ransomware and adversaries’ tools that our experts observed throughout the year in real-life incidents that required both comprehensive IR unit support and consulting services aimed at assisting organizations’ in-house expert teams.
Download the full version of the rep
Wiz
Crying Out Cloud Newsletter - March 2025 | Wiz
blogs_wiz·2025-03-01·CVSS 9.8
CVE-2025-0108 [CRITICAL] Crying Out Cloud Newsletter - March 2025 | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – noteworthy incidents, exclusive data, and crucial vulnerabilities. Let's dive in.
Here are our top picks of cloud security highlights!
Hype or no hype – Authentication Bypass Vulnerability in PAN-OS Exploited in-the-Wild
Attackers are actively exploiting CVE-2025-0108, a high-severity authentication bypass vulnerability in Palo Alto Networks PAN-OS firewalls. The flaw allows unauthenticated attackers with network access to invoke PHP scripts and potentially compromise firewall integrity and confidentiality. Researchers at Assetnote disclosed exploitation details, and active attacks have been observed since February 13, 2025.
At first, the value of this vulnerability for attackers was slightly unclear, since it “
Bleepingcomputer
BadPilot network hacking campaign fuels Russian SandWorm attacks
blogs_bleepingcomputer·2025-02-12
BadPilot network hacking campaign fuels Russian SandWorm attacks
## BadPilot network hacking campaign fuels Russian SandWorm attacks
## Bill Toulas
A subgroup of the Russian state-sponsored hacking group APT44, also known as 'Seashell Blizzard' and 'Sandworm', has been targeting critical organizations and governments in a multi-year campaign dubbed 'BadPilot.'
The threat actor has been active since at least 2021 and is also responsible for breaching networks of organizations in energy, oil and gas, telecommunications, shipping, and arms manufacturing sectors.
Microsoft's Threat Intelligence team says that the actor is dedicated to achieving initial access to target systems, establishing persistence, and maintaining presence to allow other APT44 subgroups with post-compromise expertise to take over.
"We have also observed the initial access subgroup
Tenable
Salt Typhoon: An Analysis of Vulnerabilities Exploited by this State-Sponsored Actor
blogs_tenable·2025-01-23
Salt Typhoon: An Analysis of Vulnerabilities Exploited by this State-Sponsored Actor
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
Attackers exploiting a patched FortiClient EMS vulnerability in the wild
blogs_securelist·2024-12-19
Attackers exploiting a patched FortiClient EMS vulnerability in the wild
Table of Contents
Introduction
Identification and containment
Analysis and initial vector
Analysis of telemetry data for similar threat-related cases
An ever-evolving “approach” to abusing the vulnerability in similar incidents
Tactics, techniques and procedures
Conclusion
Indicators of Compromise
Applications/Filenames from the incident
HASH – SHA1 from the incident
Domains / IP addresses from the incident
Domains / IP addresses from additional malicious payloads discovered
Authors
Ashley Muñoz
Francesco Figurelli
Cristian Souza
Eduardo Ovalle
Areg Baghinyan
## Introduction
During a recent incident response, Kaspersky’s GERT team identified a set of TTPs and indicators linked to an attacker that infiltrated a company’s networks by targeting a Fortinet vulnerability for
Securelist
Attackers exploiting a FortiClient EMS vulnerability in the wild
blogs_securelist·2024-12-19
Attackers exploiting a FortiClient EMS vulnerability in the wild
Table of Contents
- Introduction
- Identification and containment
- Analysis and initial vector
- Analysis of telemetry data for similar threat-related cases
- An ever-evolving “approach” to abusing the vulnerability in similar incidents
- Tactics, techniques and procedures
- Conclusion
- Indicators of Compromise
Authors
- Ashley Muñoz
- Francesco Figurelli
- Cristian Souza
- Eduardo Ovalle
- Areg Baghinyan
## Introduction
During a recent incident response, Kaspersky’s GERT team identified a set of TTPs and indicators linked to an attacker that infiltrated a company’s networks by targeting a Fortinet vulnerability for which a patch was already available.
This vulnerability is an improper filtering of SQL command input making the system susceptible to an SQL injection. It specifically
Trendmicro
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
blogs_trendmicro·2024-11-25
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
APT & Targeted Attacks
## Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
Since 2023, APT group Earth Estries has aggressively targeted key industries globally with sophisticated techniques and new backdoors, like GHOSTSPIDER and MASOL RAT, for prolonged espionage operations.
By: Leon M Chang, Theo Chen, Lenart Bermejo, Ted Lee Nov 25, 2024 Read time: ( words)
Save to Folio
## Summary
Earth Estries, a Chinese APT group, has primarily targeted critical sectors like telecommunications and government entities across the US, Asia-Pacific, Middle East, and South Africa since 2023.
The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian telecommunications companies and governm
Trendmicro
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
blogs_trendmicro·2024-11-25
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
APT y ataques dirigidos
## Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
Since 2023, APT group Earth Estries has aggressively targeted key industries globally with sophisticated techniques and new backdoors, like GHOSTSPIDER and MASOL RAT, for prolonged espionage operations.
By: Leon M Chang, Theo Chen, Lenart Bermejo, Ted Lee Nov 25, 2024 Read time: ( words)
Save to Folio
## Summary
Earth Estries, a Chinese APT group, has primarily targeted critical sectors like telecommunications and government entities across the US, Asia-Pacific, Middle East, and South Africa since 2023.
The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian telecommunications companies and govern
Bleepingcomputer
Salt Typhoon hackers backdoor telcos with new GhostSpider malware
blogs_bleepingcomputer·2024-11-25
Salt Typhoon hackers backdoor telcos with new GhostSpider malware
## Salt Typhoon hackers backdoor telcos with new GhostSpider malware
## Bill Toulas
The Chinese state-sponsored hacking group Salt Typhoon has been observed utilizing a new "GhostSpider" backdoor in attacks against telecommunication service providers.
The backdoor was discovered by Trend Micro, which has been monitoring Salt Typhoon's attacks against critical infrastructure and government organizations worldwide.
Along with GhostSpider, Trend Micro discovered that the threat group also uses a previously documented Linux backdoor named 'Masol RAT,' a rootkit named 'Demodex,' and a modular backdoor shared among Chinese APT groups named 'SnappyBee.'
## Salt Typhoon's global campaigns
Salt Typhoon (aka 'Earth Estries', 'GhostEmperor', or 'UNC2286') is a sophisticated hacking group that h
Trendmicro
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
blogs_trendmicro·2024-11-25
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
APT & Targeted Attacks
## Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
Since 2023, APT group Earth Estries has aggressively targeted key industries globally with sophisticated techniques and new backdoors, like GHOSTSPIDER and MASOL RAT, for prolonged espionage operations.
By: Leon M Chang, Theo Chen, Lenart Bermejo, Ted Lee 2024/11/25 Read time: ( words)
Save to Folio
## Summary
Earth Estries, a Chinese APT group, has primarily targeted critical sectors like telecommunications and government entities across the US, Asia-Pacific, Middle East, and South Africa since 2023.
The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian telecommunications companies and governmen
Trendmicro
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
blogs_trendmicro·2024-11-25
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
APT & Targeted Attacks
# Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
Since 2023, APT group Earth Estries has aggressively targeted key industries globally with sophisticated techniques and new backdoors, like GHOSTSPIDER and MASOL RAT, for prolonged espionage operations.
By: Leon M Chang, Theo Chen, Lenart Bermejo, Ted Lee
2024/11/25
Read time: ( words)
Save to Folio
#### Summary
- Earth Estries, a Chinese APT group, has primarily targeted critical sectors like telecommunications and government entities across the US, Asia-Pacific, Middle East, and South Africa since 2023.
- The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian telecommunications companies and gove
Talos
Akira ransomware continues to evolve
blogs_talos·2024-10-21
Akira ransomware continues to evolve
## Akira ransomware continues to evolve
Akira continues to cement its position as one of the most prevalent ransomware operations in the threat landscape, according to Cisco Talos’ findings and analysis.
Their success is partly due to the fact that they are constantly evolving. For example, after Akira already developed a new version of their ransomware encryptor earlier in the year, we just recently observed another novel iteration of the encryptor targeting Windows and Linux hosts alike.
Previously, Akria typically employed a double-extortion tactic in which critical data is exfiltrated prior to the compromised victim systems becoming encrypted. Beginning in early 2024, Akira appeared to be sidelining the encryption tactics, focusing on data exfiltration only. We assess with low to mo
Talos
Akira ransomware continues to evolve
blogs_talos·2024-10-21
Akira ransomware continues to evolve
Akira continues to cement its position as one of the most prevalent ransomware operations in the threat landscape, according to Cisco Talos’ findings and analysis.
Their success is partly due to the fact that they are constantly evolving. For example, after Akira already developed a new version of their ransomware encryptor earlier in the year, we just recently observed another novel iteration of the encryptor targeting Windows and Linux hosts alike.
Previously, Akria typically employed a double-extortion tactic in which critical data is exfiltrated prior to the compromised victim systems becoming encrypted. Beginning in early 2024, Akira appeared to be sidelining the encryption tactics, focusing on data exfiltration only. We assess with low to moderate confidence that this shift was due
Tenable
Cybersecurity Snapshot: RansomHub Group Triggers CISA Warning, While FBI Says North Korean Hackers Are Targeting Crypto Orgs
blogs_tenable·2024-09-06
Cybersecurity Snapshot: RansomHub Group Triggers CISA Warning, While FBI Says North Korean Hackers Are Targeting Crypto Orgs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Cybersecurity Threat Landscape 2024 Midyear Review
blogs_qualys·2024-08-06
Cybersecurity Threat Landscape 2024 Midyear Review
## Table of Contents
Key Takeaways from the Threat Landscape Report 2024
Vulnerability and Threat Analysis in the Cybersecurity Landscape 2024
Cyber Threat Landscape 2024 A Detailed Review
Key Statistics and Their Impact on the 2024 Cybersecurity Landscape
Mid-2024s Most Exploited Vulnerabilities in the Cybersecurity Landscape
Conclusion
As we navigate the complexities of 2024, it’s crucial to pause and reflect on the evolving threat landscape that surrounds us. This moment offers a unique opportunity to scrutinize our triumphs and missteps, understand the events that have decisively shaped our environment, and consider those that have subtly influenced it. By extracting key lessons from our recent experiences, we can fortify our strategies and prepare more effectively for the emerg
Qualys
Qualys Midyear 2024 Threat Landscape Analysis and Insights | Qualys
blogs_qualys·2024-08-06
Qualys Midyear 2024 Threat Landscape Analysis and Insights | Qualys
#### Table of Contents
- Key Takeaways from the Threat Landscape Report 2024
- Vulnerability and Threat Analysis in the Cybersecurity Landscape 2024
- Cyber Threat Landscape 2024 A Detailed Review
- Key Statistics and Their Impact on the 2024 Cybersecurity Landscape
- Mid-2024s Most Exploited Vulnerabilities in the Cybersecurity Landscape
- Conclusion
As we navigate the complexities of 2024, it’s crucial to pause and reflect on the evolving threat landscape that surrounds us. This moment offers a unique opportunity to scrutinize our triumphs and missteps, understand the events that have decisively shaped our environment, and consider those that have subtly influenced it. By extracting key lessons from our recent experiences, we can fortify our strategies and prepare more effectively for
Huntress
Attack Behaviors | Huntress
blogs_huntress·2024-05-30
Attack Behaviors | Huntress
In a Vertex blog post published on April 16, 2024 , Jennifer Kolde shared some profound insight regarding “threat clusters,” illustrated in Figure 1.
The key words we’re going to look at from Jennifer’s statement are “habits” and “past behaviors.”
Within the security operations center (SOC) and digital forensics and incident response (DFIR) communities, we often hear analysts say that “threat actors can change their tactics,” and on occasion, we hear a slight variation of the phrase, “threat actors always change their tactics.” The addition of the absolute changes the perspective significantly, and leaves us asking, “Okay, so what’s the point of detections and monitoring?”
The simple fact is, Jennifer is right. Threat actors are people, and as such, have tactics, techniques, and tools t
Bleepingcomputer
Exploit released for Fortinet RCE bug used in attacks, patch now
blogs_bleepingcomputer·2024-03-21·CVSS 9.8
CVE-2023-48788 [CRITICAL] Exploit released for Fortinet RCE bug used in attacks, patch now
## Exploit released for Fortinet RCE bug used in attacks, patch now
## Sergiu Gatlan
Security researchers have released a proof-of-concept (PoC) exploit for a critical vulnerability in Fortinet's FortiClient Enterprise Management Server (EMS) software, which is now actively exploited in attacks.
Tracked as CVE-2023-48788 , this security flaw is an SQL injection in the DB2 Administration Server (DAS) component discovered and reported by the UK's National Cyber Security Centre (NCSC).
It impacts FortiClient EMS versions 7.0 (7.0.1 through 7.0.10) and 7.2 (7.2.0 through 7.2.2), and it enables unauthenticated threat actors to gain remote code execution (RCE) with SYSTEM privileges on unpatched servers in low-complexity attacks that don't require user interaction.
"An improper neutralizati
Checkpoint
18th March – Threat Intelligence Report
blogs_checkpoint·2024-03-18
CVE-2024-21408 18th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 18th March, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Nissan has revealed that the Akira ransomware attack from December 2023 has compromised the personal information of approximately 100K individuals in Australia and New Zealand. The data concerns customers, dealers and some of the employees. The breach resulted in unauthorized access to Nissan’s local IT servers, with up to 10
Tenable
CVE-2023-48788: Critical Fortinet FortiClientEMS SQL Injection Vulnerability
blogs_tenable·2024-03-14·CVSS 9.8
[CRITICAL] CVE-2023-48788: Critical Fortinet FortiClientEMS SQL Injection Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Fortinet warns of critical RCE bug in endpoint management software
blogs_bleepingcomputer·2024-03-13·CVSS 8.1
CVE-2023-48788 [HIGH] Fortinet warns of critical RCE bug in endpoint management software
## Fortinet warns of critical RCE bug in endpoint management software
## Sergiu Gatlan
Fortinet patched a critical vulnerability in its FortiClient Enterprise Management Server (EMS) software that can allow attackers to gain remote code execution (RCE) on vulnerable servers.
FortiClient EMS enables admins to manage endpoints connected to an enterprise network, allowing them to deploy FortiClient software and assign security profiles on Windows devices.
The security flaw ( CVE-2023-48788 ) is an SQL injection in the DB2 Administration Server (DAS) component, which was discovered and reported by the UK's National Cyber Security Centre (NCSC) and Fortinet developer Thiago Santana.
It impacts FortiClient EMS versions 7.0 (7.0.1 through 7.0.10) and 7.2 (7.2.0 through 7.2.2), and it allows
Threat Intel
Medusa Group (Medusa Group)
threat_intel
Medusa Group (Medusa Group)
# Threat Actor Profile: Medusa Group
ATT&CK ID: G1051
Also known as: Medusa Group
## Overview
Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” (Citation: CISA Medusa Group Medusa Ransomware March 2025) (Citation: Broadcom Medusa Ransomware Medusa Group March 2025) Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltra
Wiz
CVE-2026-21643 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-21643 [CRITICAL] CVE-2026-21643 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21643 :
FortiClient EMS vulnerability analysis and mitigation
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Source : NVD
## 9.8
Score
Published February 6, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
FortiClient EMS
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient_endpoint_management_server
Sources
Windows Severity CRITICAL Has Fix Added at: Feb 11
Greynoiseio
NoiseLetter March 2024
blogs_greynoiseio
NoiseLetter March 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Wiz
CVE-2026-35616 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-35616 [CRITICAL] CVE-2026-35616 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-35616 :
FortiClient EMS vulnerability analysis and mitigation
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Source : NVD
## 9.8
Score
Published April 4, 2026
Severity CRITICAL
CNA Score 9.8
High-profile Vulnerability Yes
Affected Technologies
FortiClient EMS
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 90.6
Exploitation Probability (EPSS) 6
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient_enterprise_management_server
Sources
Windows Severity CRITICAL Has Fix Added at: Apr 05, 2026
## Get a CVE risk assessmen
Huntress
Attack Behaviors | Huntress
blogs_huntress
Attack Behaviors | Huntress
In a Vertex blog post published on April 16, 2024, Jennifer Kolde shared some profound insight regarding “threat clusters,” illustrated in Figure 1.
Fig. 1: Vertex blog excerpt
The key words we’re going to look at from Jennifer’s statement are “habits” and “past behaviors.”
Within the security operations center (SOC) and digital forensics and incident response (DFIR) communities, we often hear analysts say that “threat actors can change their tactics,” and on occasion, we hear a slight variation of the phrase, “threat actors always change their tactics.” The addition of the absolute changes the perspective significantly, and leaves us asking, “Okay, so what’s the point of detections and monitoring?”
The simple fact is, Jennifer is right. Threat actors are people, and as such, have tact
arXiv
Efficacy of EPSS in High Severity CVEs found in KEV
arxiv_fulltext·2024-11-04
Efficacy of EPSS in High Severity CVEs found in KEV
empty
empty
24pt
10pt plus 1.0pt minus 2.0pt
## Abstract
The Exploit Prediction Scoring System (EPSS) is designed to assess the probability of a vulnerability being exploited in the next 30 days relative to other vulnerabilities. The latest version, based on a research paper published in arXiv , assists defenders in deciding which vulnerabilities to prioritize for remediation. This study evaluates EPSS's ability to predict exploitation before vulnerabilities are actively compromised, focusing on high severity CVEs that are known to have been exploited and included in the CISA KEV catalog. By analyzing EPSS score history, the availability and simplicity of exploits, the system's purpose, its value as a target for Threat Actors (TAs), this paper examines EPSS's potential and identifies ar
2024-03-12
Published
2024-03-25
Added to CISA KEV
Exploited in the wild