Product
high
advisory
DNS Kerberos Coercion Attempt Detection
3 rules 3 TTPs 4 CVEs 4 IOCsThis brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.
PoC
Fortinet edge appliances +38
kerberos
coercion
dns
cve-2025-33073
3r
3t
4c
4i
updated
critical
advisory
Fortinet Appliance Authentication Bypass Vulnerability (CVE-2022-40684) Exploitation
2 rules 2 TTPsExploitation of CVE-2022-40684, a Fortinet appliance authentication bypass vulnerability, allows unauthorized REST API access to modify system configurations, potentially leading to complete system compromise.
FortiOS +2
cve-2022-40684
fortinet
authentication-bypass
network-appliance
initial-access
2r
2t