FOFA - Tool

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
November 18, 2025
Last Seen
August 2, 2026

FOFA is a tool tracked by ThreatCluster, appearing in 5 threat clusters built from 7 intelligence report mentions.

FOFA is a tool tracked across 5 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed November 18, 2025; most recent activity August 2, 2026.

Related Threat Clusters

  • FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation

    A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…

    100 articles · Updated November 15, 2025
  • Bulgaria's Circles Exports Surveillance Tech to Rights Violators

    Between 2018 and 2023, Bulgaria licensed the export of surveillance technology from Circles, a company linked to NSO Group, to various countries with histories of human rights abuses. Human Rights Watch revealed that…

    9 articles · Updated June 19, 2026
  • DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor

    A Chinese-speaking threat actor, identified as knaithe/KnYuan, executed an autonomous cyberattack campaign using DeepSeek AI and the Hermes Agent framework. The campaign targeted over 460 servers, attempting to exploit…

    5 articles · Updated August 2, 2026
  • Critical Vulnerabilities in Fortinet FortiWeb Actively Exploited

    Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows…

    74 articles · Updated November 28, 2025
  • Time to Exploit Vulnerabilities Drops 94% in Five Years

    A study by Flashpoint reveals that the time to exploit vulnerabilities has decreased from 745 days in 2020 to just 44 days in 2025. This significant reduction is attributed to the rise of n-day vulnerabilities, which…

    4 articles · Updated February 12, 2026

Recent Intelligence Reports

  • BleepingComputer summarised the finding — www.bleepingcomputer.com · August 2, 2026
  • DeepSeek Became the Attack Engine Because It Had the Fewest Guardrails — Forkast.News · August 1, 2026
  • DeepSeek Ran Autonomous Cyberattacks That Claude and OpenAI Safety Controls Blocked — Techtimes · August 1, 2026
  • Running In Circles Uncovering The Clients Of Cyberespionage Firm Circles — citizenlab.ca · June 19, 2026
  • Time to Exploit Plummets as N — Infosecurity-Magazine · February 12, 2026
  • N-Day Vulnerability Trends: The Shrinking Window of Exposure and the Rise of "Turn — Flashpoint · February 11, 2026
  • Fortinet’s silent patch sparks alarm as a critical FortiWeb flaw is exploited in the wild — Csoonline · November 18, 2025

Frequently asked questions

What is FOFA?

FOFA is a tool tracked by ThreatCluster, appearing in 5 threat clusters built from 7 intelligence report mentions.

Is FOFA still active?

The most recent intelligence report mentioning FOFA on ThreatCluster is dated August 2, 2026. Activity was first observed November 18, 2025, giving a tracked span from then to August 2, 2026.

What is FOFA associated with?

Across ThreatCluster reporting, FOFA most frequently co-occurs with Knaithe/KnYuan, Lazarus, Data Breach, Malware, Zero-day Exploit, among 12 tracked related entities.

What are the latest developments involving FOFA?

The most significant recent cluster is “FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation” (100 articles · Updated November 15, 2025). FOFA appears across 5 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on FOFA?

FOFA appears in 7 intelligence report mentions across 5 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown