{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/fortiproxy/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["Qilin","Agenda"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["www.acosol.es","vCenter","ESXi","Cloud Sensor AV","VMware vCenter","VMware ESXi","Carbon Black Cloud Sensor AV","Toshiba power management driver","NetSupport","ScreenConnect","Zemana Anti-Rootkit driver","www.nuevaschool.org","Apache bRPC","FortiOS","FortiProxy","SmarterMail","Telnetd in GNU Inetutils","WatchGuard Fireware OS","Check Point VPN Remote Access and Mobile Access","Veeam Backup \u0026 Replication","SolarWinds Web Help Desk","Zemana AntiLogger","VPN Remote Access and Mobile Access","Backup \u0026 Replication","www.rehavital.de","EasyUpload.io","MEGA","VPN Remote Access","Mobile Access","www.triton.com.pe","www.api.com.ph","Telnetd","Fireware OS","Web Help Desk","AntiLogger","vCenters","FortiOS \u0026 FortiProxy","Contacto Garantido","Check Point VPN Remote Access","Check Point Mobile Access","www.wilberts.com","Cloud NGFW"],"_cs_severities":["critical"],"_cs_tags":["ransomware","qilin","double-extortion","golang","agriculture","food-production"],"_cs_type":"threat","_cs_vendors":["Acosol","VMware","Carbon Black","Toshiba","Powder River Heating","Martorani","NetSupport","ScreenConnect","Zemana","Cityambu","Famesa","Apache","Fortinet","SmarterTools","Telnet","WatchGuard","Check Point","Veeam","SolarWinds","RehaVital Gesundheitsservice GmbH","GNU","EZ Systems","MEGA","Qilin","GNU Inetutils","Triton","API","Microsoft","Palo Alto Networks"],"content_html":"\u003cp\u003eThe Qilin ransomware group, a highly active threat actor first observed in July 2022, continues its double extortion operations, with a recent claim against Danone (International Delights), a US-based company in the Agriculture and Food Production sector. Qilin ransomware is written in Golang, offering multiple encryption modes controlled by the operators, and its campaigns typically involve both data encryption and the threat of public release of stolen sensitive information if a ransom is not paid. The group has accumulated over 2000 victims across various industries, including manufacturing, business services, technology, and healthcare, primarily targeting entities in the United States. This ongoing activity highlights Qilin's persistent threat to critical infrastructure and diverse commercial enterprises globally.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Access\u003c/strong\u003e: Attackers gain entry through various methods, including the exploitation of public-facing applications, spearphishing via email, or leveraging valid but compromised accounts (e.g., T1566, T1190, T1078).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExecution\u003c/strong\u003e: Qilin operators execute malicious code using scripting interpreters like PowerShell or Unix Shell, or by deploying malicious system services (e.g., T1059.001, T1059.004, T1569.002).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePersistence \u0026amp; Privilege Escalation\u003c/strong\u003e: Persistence is established via scheduled tasks or boot/logon autostart execution. Privilege escalation is achieved through exploitation of vulnerabilities or techniques like OS credential dumping (e.g., T1053.005, T1547, T1068, T1003.001).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDefense Evasion\u003c/strong\u003e: The group employs techniques such as obfuscated files, modifying or disabling security tools, and impairing system defenses like firewalls to maintain access and avoid detection (e.g., T1027, T1562, T1562.004).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDiscovery \u0026amp; Lateral Movement\u003c/strong\u003e: Attackers conduct extensive network reconnaissance, querying registries, sniffing network traffic, and using remote services (e.g., SMB/Windows Admin Shares, RDP) to identify high-value targets and move laterally across the compromised network (e.g., T1012, T1046, T1021.001, T1021.002).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCollection \u0026amp; Exfiltration\u003c/strong\u003e: Sensitive data is collected and often archived using utilities before being exfiltrated over alternative network mediums or to cloud storage services (e.g., T1560.001, T1041, T1567.002).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCommand and Control\u003c/strong\u003e: Communication with C2 infrastructure is maintained through various methods, including obfuscated data and tunneling over common application layer protocols like web protocols (e.g., T1001, T1071.001, T1572).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact\u003c/strong\u003e: The final stage involves encrypting victim data, inhibiting system recovery mechanisms, and sometimes wiping disks to maximize disruption and coerce ransom payment (e.g., T1486, T1490, T1488, T1488.001).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe Qilin ransomware group's attacks result in severe operational disruption, data loss due to encryption, and potential public exposure of sensitive information through their double extortion model. With over 2000 victims reported since 2022, including a recent target in the US Agriculture and Food Production sector, the scope of their impact is significant and spans diverse industries like manufacturing, business services, technology, and healthcare. Successful attacks lead to direct financial losses from ransom demands, costs associated with incident response and recovery, and severe reputational damage. The loss of critical business data and systems can halt operations for extended periods, impacting supply chains and essential services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement endpoint detection and response (EDR) solutions to detect and block malicious hashes listed in the IOCs.\u003c/li\u003e\n\u003cli\u003eBlock connections to the malicious IP addresses and domains listed in the IOC table at the network perimeter firewall and DNS resolver.\u003c/li\u003e\n\u003cli\u003eDeploy and tune endpoint security rules, such as the \u003ccode\u003eDetect Qilin Ransomware Hashes\u003c/code\u003e rule, to identify and quarantine known Qilin ransomware samples.\u003c/li\u003e\n\u003cli\u003eImplement and continuously monitor the \u003ccode\u003eDetect Qilin C2 Network Connections\u003c/code\u003e rule to identify and alert on suspicious outbound network activity to known Qilin infrastructure.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive logging for process creation, network connections, and file events on all endpoints to provide visibility for the detection rules and facilitate incident response.\u003c/li\u003e\n\u003cli\u003eReview and enforce strong password policies and multi-factor authentication (MFA) to mitigate initial access attempts via valid accounts (ATT\u0026amp;CK T1078).\u003c/li\u003e\n\u003cli\u003eRegularly patch and update all public-facing applications and systems to prevent exploitation of vulnerabilities (ATT\u0026amp;CK T1190).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T13:38:00Z","date_published":"2026-07-15T20:00:29Z","id":"https://feed.craftedsignal.io/briefs/2026-07-qilin-ransomware/","summary":"The Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.","title":"Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector","url":"https://feed.craftedsignal.io/briefs/2026-07-qilin-ransomware/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-6875"},{"cvss":4,"id":"CVE-2026-14902"},{"cvss":7.7,"id":"CVE-2026-14903"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Brazil (prior to Brazil EA)","Brazil (prior to Brazil GA)","Australia (prior to Australia Patch 2)","Zurich (prior to Zurich Patch 7b)","Zurich (prior to Zurich Patch 9)","Yokohama (prior to Yokohama Patch 12 Hot Fix 1b)","Yokohama (prior to Yokohama Patch 13)","ServiceNow AI platform","Xtraction","FortiOS","FortiProxy","FortiSASE","FortiSIEM","FortiClient EMS","FortiAuthenticator","FortiPAM","FortiSwitch Manager","FortiSwitch-Manager Agentless SSL-VPN","FortiSandbox"],"_cs_severities":["high"],"_cs_tags":["vulnerability","servicenow","cloud"],"_cs_type":"threat","_cs_vendors":["ServiceNow","Ivanti","Fortinet"],"content_html":"\u003cp\u003eOn July 13, 2026, ServiceNow issued a security advisory (AV26-693) detailing a critical sandbox escape vulnerability, identified as CVE-2026-6875, within its AI Platform. This vulnerability affects several versions across multiple product lines, specifically Brazil (prior to EA and GA releases), Australia (prior to Patch 2), Zurich (prior to Patch 7b and Patch 9), and Yokohama (prior to Patch 12 Hot Fix 1b and Patch 13). A sandbox escape allows an attacker to break out of a restricted execution environment, potentially gaining unauthorized access to underlying systems or sensitive data with higher privileges. While the advisory does not specify observed exploitation in the wild, the critical nature of a sandbox escape warrants immediate attention for organizations utilizing these ServiceNow products to prevent potential data compromise, system disruption, or further network infiltration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-6875 could allow an attacker to bypass the security restrictions of the ServiceNow AI Platform's sandbox environment. This could lead to unauthorized access to sensitive data, execution of arbitrary code outside the sandbox, or escalation of privileges on the affected ServiceNow instance. While no specific victims or attack campaigns have been detailed in the advisory, any organization using the vulnerable versions of ServiceNow Brazil, Australia, Zurich, or Yokohama platforms is at risk of severe impact, including data breaches, system integrity compromise, and operational disruption if the vulnerability is exploited by a malicious actor.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReview the ServiceNow Security Advisory (KB3137947) linked in this brief immediately to understand the specific affected versions and apply the necessary patches for CVE-2026-6875.\u003c/li\u003e\n\u003cli\u003eApply the recommended updates to your ServiceNow Brazil instances (prior to Brazil EA and Brazil GA), Australia instances (prior to Australia Patch 2), Zurich instances (prior to Zurich Patch 7b and Zurich Patch 9), and Yokohama instances (prior to Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13).\u003c/li\u003e\n\u003cli\u003eEnsure that all ServiceNow platforms are kept up-to-date with the latest security patches to mitigate known vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-15T11:05:50Z","date_published":"2026-07-14T14:38:44Z","id":"https://feed.craftedsignal.io/briefs/2026-07-servicenow-sandbox-escape/","summary":"ServiceNow has released a security advisory addressing CVE-2026-6875, a critical sandbox escape vulnerability affecting multiple product versions including Brazil, Australia, Zurich, and Yokohama, which could allow an attacker to bypass security boundaries and execute arbitrary code with elevated privileges.","title":"ServiceNow Critical Sandbox Escape Vulnerability (CVE-2026-6875)","url":"https://feed.craftedsignal.io/briefs/2026-07-servicenow-sandbox-escape/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Fortinet edge appliances","Cisco edge appliances","OWA/M365","BIG-IP Virtual Edition (VE)","Confluence Data Center","Microsoft Defender XDR","Defender","BIG-IP","Confluence","Exchange Server","nx.dev","Metasploit","VMware Aria Operations","Fortinet FortiGate","Cisco","Microsoft software","Rocket.Chat","Fortinet firewalls","Fortinet VPN gateways","FortiCloud SSO Login","FortiGate","FortiCloud SSO","FortiOS","FortiCloud","FortiManager","FortiAnalyzer","FortiProxy","FortiSwitchManager","FortiWeb","Erlang/OTP SSH server","Windows SMB Client","ThrottleStop","ESXi","Erlang/OTP (\u003c= 27.3.1)","Erlang/OTP (\u003c= 26.2.5)","RabbitMQ Server","Riak","CouchDB"],"_cs_severities":["high"],"_cs_tags":["kerberos","coercion","dns","cve-2025-33073"],"_cs_type":"advisory","_cs_vendors":["Fortinet","Cisco","Microsoft","F5","Atlassian","VMware","SAP","Ivanti","GitHub","Nx","Rocket.Chat","Erlang","TechPowerUp","RabbitMQ","Riak","CouchDB"],"content_html":"\u003cp\u003eThis brief addresses the threat of DNS-based Kerberos coercion attacks, which are designed to compromise authentication processes within a network. Attackers inject specifically crafted marshaled credential structures, identified by patterns like '\u003cem\u003e1UWhRC\u003c/em\u003e', '\u003cem\u003eAAAAA\u003c/em\u003e', and '\u003cem\u003eYBAAAA\u003c/em\u003e', into DNS records. This injection allows the attacker to spoof Service Principal Names (SPNs) and redirect authentication requests, potentially leading to unauthorized access and lateral movement. The attack leverages vulnerabilities such as CVE-2025-33073. This activity has been observed leveraging both Suricata network monitoring and Windows Sysmon (Event ID 22) to detect the presence of these malicious DNS queries. Detection of this activity is critical to prevent Kerberos relay attacks and maintain the integrity of network authentication.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker gains initial access to a compromised host within the network.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious DNS query containing marshaled \u003ccode\u003eCREDENTIAL_TARGET_INFORMATION\u003c/code\u003e structures.\u003c/li\u003e\n\u003cli\u003eThe compromised host sends the malicious DNS query to the internal DNS server.\u003c/li\u003e\n\u003cli\u003eThe DNS server processes the query, unknowingly forwarding the malicious data.\u003c/li\u003e\n\u003cli\u003eThe attacker intercepts the DNS response and uses the spoofed SPN to initiate a Kerberos authentication request.\u003c/li\u003e\n\u003cli\u003eThe target server authenticates to the attacker-controlled service, relaying credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the relayed credentials to gain unauthorized access to network resources.\u003c/li\u003e\n\u003cli\u003eThe attacker escalates privileges and moves laterally within the network, achieving their final objective.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eA successful Kerberos coercion attack can lead to significant compromise of a network. By relaying credentials, attackers can gain unauthorized access to critical systems and data. While the exact number of potential victims is unknown, the impact can range from data breaches to complete network takeover. Sectors relying on Kerberos for authentication, such as government, finance, and healthcare, are particularly vulnerable. Successful exploitation allows attackers to escalate privileges, move laterally, and ultimately achieve their objectives, including data exfiltration or ransomware deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure that DNS data is properly ingested and correlated with the Network Resolution data model in your SIEM to facilitate detection using the provided search query.\u003c/li\u003e\n\u003cli\u003eImplement the provided Sigma rules to detect suspicious DNS queries containing marshaled credential structures based on Suricata and Sysmon event ID 22 logs.\u003c/li\u003e\n\u003cli\u003eInvestigate and patch CVE-2025-33073 on all affected systems to prevent exploitation of the vulnerability.\u003c/li\u003e\n\u003cli\u003eReview and tune the provided Sigma rules for false positives, filtering as needed for your organization's specific environment based on the known false positives.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon Event ID 22 logging to enhance visibility into DNS query activity on Windows endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T07:06:14Z","date_published":"2024-01-03T12:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-03-dns-kerberos-coercion/","summary":"This brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.","title":"DNS Kerberos Coercion Attempt Detection","url":"https://feed.craftedsignal.io/briefs/2024-01-03-dns-kerberos-coercion/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FortiOS","FortiProxy","FortiSwitchManager"],"_cs_severities":["critical"],"_cs_tags":["cve-2022-40684","fortinet","authentication-bypass","network-appliance","initial-access"],"_cs_type":"advisory","_cs_vendors":["Fortinet"],"content_html":"\u003cp\u003eCVE-2022-40684 is an authentication bypass vulnerability affecting Fortinet appliances, specifically FortiOS, FortiProxy, and FortiSwitchManager. Successful exploitation allows a remote attacker to bypass authentication and perform unauthorized administrative actions via crafted HTTP requests. Public exploits and Metasploit modules targeting this vulnerability were quickly developed and released after the vulnerability was disclosed in late 2022. The vulnerability stems from an improper access control issue, allowing attackers to interact with the REST API without proper authentication. The primary targets are organizations using unpatched Fortinet appliances, and the impact can range from data theft and denial of service to complete network compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a vulnerable Fortinet appliance exposed to the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP request to the \u003ccode\u003e/api/v2/cmdb/system/admin\u003c/code\u003e endpoint, bypassing authentication checks.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the \u003ccode\u003ePUT\u003c/code\u003e or \u003ccode\u003ePOST\u003c/code\u003e HTTP methods to modify existing administrator accounts or create new accounts.\u003c/li\u003e\n\u003cli\u003eThe attacker adds an SSH key to an administrator account to gain persistent remote access.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the newly created or modified administrator account to log into the Fortinet appliance's web interface or SSH.\u003c/li\u003e\n\u003cli\u003eThe attacker reconfigures firewall rules to allow unauthorized network traffic.\u003c/li\u003e\n\u003cli\u003eThe attacker exfiltrates sensitive data from the network through the compromised Fortinet appliance.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the compromised appliance as a pivot point to access other internal systems.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2022-40684 can lead to complete compromise of the Fortinet appliance and the network it protects. Attackers can gain unauthorized access to sensitive data, disrupt network services, and use the compromised appliance as a foothold for further attacks within the network. This vulnerability has been widely exploited, impacting numerous organizations across various sectors. Unpatched systems are at high risk of being compromised.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the latest Fortinet patches to address CVE-2022-40684 on all FortiOS, FortiProxy, and FortiSwitchManager appliances immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eFortinet Appliance Auth Bypass Attempt\u003c/code\u003e to your SIEM to detect exploitation attempts targeting the \u003ccode\u003e/api/v2/cmdb/system/admin\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eEnable web server logging on Fortinet appliances to ensure the Sigma rule can effectively detect malicious activity.\u003c/li\u003e\n\u003cli\u003eReview existing user accounts and SSH keys for any unauthorized additions or modifications.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for suspicious outbound connections originating from Fortinet appliances.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to limit the impact of a successful breach.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2024-01-03T10:00:00Z","date_published":"2024-01-03T10:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-03-fortinet-auth-bypass/","summary":"Exploitation of CVE-2022-40684, a Fortinet appliance authentication bypass vulnerability, allows unauthorized REST API access to modify system configurations, potentially leading to complete system compromise.","title":"Fortinet Appliance Authentication Bypass Vulnerability (CVE-2022-40684) Exploitation","url":"https://feed.craftedsignal.io/briefs/2024-01-03-fortinet-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - FortiProxy","version":"https://jsonfeed.org/version/1.1"}