Related Threat Clusters
-
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Cyber Adversaries Exploit File Enumeration and Data Collection Techniques
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
2 articles · Updated April 22, 2026 -
Over 10,000 Fortinet Firewalls Vulnerable to 2FA Bypass Exploits
More than 10,000 Fortinet firewalls remain exposed to a critical two-factor authentication bypass vulnerability (CVE-2020-12812) that has been actively exploited. This flaw, first disclosed in July 2020, continues to…
6 articles · Updated January 5, 2026 -
Fortinet Addresses Critical SSO Authentication Bypass Vulnerabilities
Fortinet has released security updates for critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication. The vulnerabilities,…
3 articles · Updated December 10, 2025 -
Critical Vulnerabilities in Fortinet FortiWeb Actively Exploited
Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows…
74 articles · Updated November 28, 2025 -
Over 25,000 Fortinet Devices Vulnerable to Attacks via FortiCloud SSO
More than 25,000 Fortinet devices with FortiCloud SSO enabled are exposed to remote attacks due to a critical authentication bypass vulnerability tracked as CVE-2025-59718. The U.S. has the highest number of affected…
2 articles · Updated December 22, 2025
Recent Intelligence Reports
- T1027 — attack.mitre.org · August 7, 2026
- T1083 — attack.mitre.org · April 22, 2026
- Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass — Bleepingcomputer · January 2, 2026
- Over 25,000 FortiCloud SSO devices exposed to remote attacks — Bleepingcomputer · December 19, 2025
- Fortinet warns of critical FortiCloud SSO login auth bypass flaws — Bleepingcomputer · December 9, 2025
- CISA gives govt agencies 7 days to patch new Fortinet flaw — Bleepingcomputer · November 19, 2025
- Fortinet warns of new FortiWeb zero — Bleepingcomputer · November 18, 2025