Skip to content
Threat Feed

Vendor

Fortinet

16 briefs RSS
critical threat

FortiBleed Campaign: 73,932 FortiGate Systems Credentials Exposed

A Russian-speaking threat group utilized a large dataset of administrative and VPN credentials, likely sourced from exposed FortiGate configuration files and active credential harvesting, to access government, critical infrastructure, and multinational corporate networks, resulting in widespread data exfiltration.

FortiGate +1 Russian-speaking threat group credential-theft fortios state-sponsored espionage data-exfiltration russian-speaking critical-infrastructure government
3r 9t 1i
critical advisory

Multiple Critical Vulnerabilities in Fortinet Products Lead to RCE and Data Exposure

Multiple critical vulnerabilities (CVE-2025-67862, CVE-2026-25089, CVE-2026-49938) have been discovered across Fortinet products including FortiOS, FortiPortal, FortiProxy, and FortiSandbox, enabling unauthenticated attackers to achieve remote arbitrary code execution and compromise data confidentiality.

FortiOS +11 remote-code-execution data-exfiltration vulnerability fortinet network-appliance
2r 4t 3c 6i
high advisory

First-Time FortiGate Administrator Login Detected

A user with the Administrator role has successfully logged in to the FortiGate management interface for the first time within the last 5 days, potentially indicating unauthorized access or misconfiguration.

FortiGate initial-access administrator-login
2r 1t
medium threat

Fortinet FortiAnalyzer and FortiManager Vulnerability Allows Denial of Service

A remote, authenticated attacker can exploit a vulnerability in Fortinet FortiAnalyzer and FortiManager to perform a denial-of-service attack, disrupting normal operations.

FortiAnalyzer +1 denial-of-service fortinet network
2r 1t
critical advisory

Fortinet FortiSandbox Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in Fortinet FortiSandbox to execute arbitrary program code, potentially leading to system compromise.

FortiSandbox fortinet rce vulnerability
2r 1t
high advisory

Fortinet FortiOS Privilege Escalation Vulnerability

An authenticated remote attacker can exploit a vulnerability in Fortinet FortiOS to escalate their privileges.

FortiOS privilege-escalation fortinet
2r 1t
critical threat

Multiple Vulnerabilities in Fortinet Products Could Allow for Remote Code Execution

Multiple vulnerabilities in Fortinet's FortiAuthenticator and FortiSandbox products could lead to remote code execution, potentially allowing attackers to install programs, modify data, or create new accounts.

FortiAuthenticator +1 vulnerability rce fortinet
2r 1t
high advisory

Fortinet Patches Multiple Vulnerabilities in FortiAuthenticator, FortiOS, and FortiSandbox

Fortinet released security advisories on May 12, 2026, addressing critical vulnerabilities including improper access control, incorrect global authorization, and out-of-bounds access across FortiAuthenticator, FortiOS, and FortiSandbox product lines, urging users to apply necessary updates.

FortiAuthenticator +20 fortinet vulnerability patch
2r
medium advisory

Potential Evasion via Windows Filtering Platform Blocking Security Software

Adversaries may add malicious Windows Filtering Platform (WFP) rules to prevent endpoint security solutions from sending telemetry data, impairing defenses, which this rule detects by identifying multiple WFP block events where the process name is associated with endpoint security software.

Windows Filtering Platform +2 defense-evasion windows-filtering-platform endpoint-security
2r 2t
high advisory

Komari Agent Abused as SYSTEM-Level Backdoor

Threat actors are abusing the Komari monitoring agent, a project hosted on GitHub, as a SYSTEM-level backdoor following initial access through compromised VPN credentials and lateral movement via Impacket.

Defender +2 komari backdoor nssm github rat reverse shell
2r 4t 2i
medium advisory

Suspicious Module Loaded by LSASS for Credential Access

Detection of unsigned or untrusted DLLs being loaded into the LSASS process, which is indicative of credential access attempts by adversaries aiming to steal sensitive information such as user passwords.

credential-access lsass windows
2r 2t
high advisory

Windows Filtering Platform Policy Added to Block EDR Process

Attackers modify the Windows Filtering Platform (WFP) policy to block the communication of endpoint detection and response (EDR) processes, impairing their functionality and hindering detection of malicious activities.

CylanceSvc.exe +15 edr-bypass defense-evasion wfp
2r 1t
high advisory

Suspicious Firewall Modification to Allow Network Discovery

Detection of 'netsh' command execution to enable network discovery in the firewall, a technique commonly used by ransomware such as REvil and RedDot to discover and compromise additional machines on the network.

Splunk Enterprise +3 ransomware lateral-movement windows
2r
high advisory

Firewall Modification for File and Printer Sharing

This analytic detects the modification of Windows Firewall settings to enable file and printer sharing, a common technique used by ransomware to facilitate lateral movement and broader network encryption.

Splunk Enterprise +3 ransomware lateral-movement windows
2r 1t
medium advisory

LSASS Loading Suspicious DLL

Detection of LSASS loading an unsigned or untrusted DLL, which can indicate credential access attempts by malicious actors targeting sensitive information stored in the LSASS process.

Windows credential-access lsass dll-injection
2r 2t 9i
high advisory

Malicious MSC File Creation in Mock Trusted Directory

The creation of MSC files within a 'C:\Windows \System32' directory can be exploited to execute malicious files due to path parsing vulnerabilities in Windows, potentially leading to privilege escalation, persistence, and defense evasion.

Splunk Enterprise +2 defense-evasion privilege-escalation persistence windows
2r 3t