Skip to content
Threat Feed

Product

FortiProxy

6 briefs RSS
low advisory

Vulnerabilities in Siemens RUGGEDCOM APE1808 via Fortinet Integration

Siemens RUGGEDCOM APE1808 devices are impacted by multiple vulnerabilities (CVE-2026-23573, CVE-2026-59839) within the integrated Fortinet NGFW software, potentially allowing remote code execution or filesystem deletion.

RUGGEDCOM APE1808 +4
2t 2c
high threat

Gunra Ransomware Gang Exploitation of Fortinet Appliances

The Gunra ransomware-as-a-service group is leveraging critical Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to gain initial access, hijack VDI sessions, and bypass multi-factor authentication in attacks against critical infrastructure.

FortiOS +1 Gunra ransomware fortinet vpn critical-infrastructure authentication-bypass
4t 2c
critical threat

Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector

The Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.

www.acosol.es +46 Qilin +1 ransomware double-extortion golang agriculture food-production
2r 13t 5c 178i updated
high threat

ServiceNow Critical Sandbox Escape Vulnerability (CVE-2026-6875)

ServiceNow has released a security advisory addressing CVE-2026-6875, a critical sandbox escape vulnerability affecting multiple product versions including Brazil, Australia, Zurich, and Yokohama, which could allow an attacker to bypass security boundaries and execute arbitrary code with elevated privileges.

exploited Brazil +18 vulnerability servicenow cloud
3c updated
high advisory

DNS Kerberos Coercion Attempt Detection

This brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.

PoC Fortinet edge appliances +38 kerberos coercion dns cve-2025-33073
3r 3t 4c 4i updated
critical advisory

Fortinet Appliance Authentication Bypass Vulnerability (CVE-2022-40684) Exploitation

Exploitation of CVE-2022-40684, a Fortinet appliance authentication bypass vulnerability, allows unauthorized REST API access to modify system configurations, potentially leading to complete system compromise.

FortiOS +2 cve-2022-40684 fortinet authentication-bypass network-appliance initial-access
2r 2t