Related Threat Clusters
-
Exploitation of FortiGate SSO Vulnerabilities by Threat Actors
Threat actors are actively exploiting critical authentication bypass vulnerabilities in Fortinet's FortiGate appliances, specifically CVE-2025-59718 and CVE-2025-59719. These vulnerabilities allow unauthenticated single…
4 articles · Updated December 16, 2025 -
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw,…
23 articles · Updated July 28, 2026 -
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
6 articles · Updated May 22, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Critical Check Point VPN Vulnerability Exploited by Ransomware Gang
Check Point Software Technologies disclosed a critical authentication bypass vulnerability (CVE-2026-50751) affecting its Remote Access VPN and Mobile Access products, with exploitation confirmed since May 7, 2026. The…
46 articles · Updated June 8, 2026 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
Critical Vulnerabilities in FortiOS and Arista VeloCloud Under Active Exploitation
Fortinet's FortiOS and Arista's VeloCloud Orchestrator On-Prem are currently under attack due to critical vulnerabilities. The FortiOS vulnerability (CVE-2025-68686) allows unauthorized access to confidential…
2 articles · Updated July 28, 2026 -
Russian Hackers Breach UK Government Email Accounts in Major Cyber Attack
A significant cyber attack attributed to Russian hackers has compromised the email accounts of UK government officials and Foreign Office staff, exposing sensitive systems and critical infrastructure. Named…
2 articles · Updated July 6, 2026 -
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks
A China-linked threat actor known as Red Menshen has been conducting a long-term espionage campaign targeting global telecommunications networks using a stealthy Linux kernel backdoor called BPFdoor. This malware…
16 articles · Updated March 26, 2026 -
Surge in Brute-Force Attacks Targeting SonicWall and Fortinet Devices
In the first quarter of 2026, a significant increase in brute-force authentication attacks was reported, primarily targeting SonicWall and Fortinet FortiGate devices. According to Barracuda, approximately 90% of these…
4 articles · Updated April 15, 2026
Recent Intelligence Reports
- Fortinet FortiWeb: Attackers can log in with any credentials — Heise.De · August 14, 2026
- Fortinet Discloses Second Firewall Auth Bypass Patched In January — www.bleepingcomputer.com · August 12, 2026
- US and South Korea warn of Gunra ransomware targeting govt agencies — Bleepingcomputer · August 11, 2026
- Hackers Cross From IT to OT Through a Private APN in Poland — Securityaffairs.Co · August 10, 2026
- FrostArmada — www.lumen.com · August 3, 2026
- Attacks on FortiOS and Arista VeloCloud Observed — www.heise.de · July 29, 2026
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — unsafe.sh · July 28, 2026
- Edge Under Siege How State Sponsored Actors Exploit Your Perimeter — www.trendmicro.com · July 23, 2026