Mr.Trunk · @mrtrunk
3 followers · 3442 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
3 followers · 3250 posts · Server dromedary.seedoubleyou.me

SecurityOnline: CVE-2023-33308: Fortinet Patches Critical RCE Vulnerability in FortiOS/FortiProxy securityonline.info/cve-2023-3 -2023-28001 -2023-33308

#cve #vulnerability #fortiproxy #fortios

Last updated 2 years ago

Raphael · @0x3e4
42 followers · 127 posts · Server shitcoin.land

"For this reason, if the customer has SSL-VPN enabled, Fortinet is advising customers to take immediate action to upgrade to the most recent firmware release. If the customer is not operating SSL-VPN the risk of this issue is mitigated – however, Fortinet still recommends upgrading."

fortinet.com/blog/psirt-blogs/

#fortinet #sysadmin #fortios #cve #security

Last updated 2 years ago

Raphael · @0x3e4
42 followers · 125 posts · Server shitcoin.land
Redhotcyber · @redhotcyber
422 followers · 688 posts · Server mastodon.bida.im

Gli exploit su Fortinet FortiOS sono stati utilizzati per colpire delle organizzazioni governative

Dei non meglio identificati hanno utilizzato i nuovi per sfruttare la di che è stata corretta all’inizio di questo mese. Gli attacchi prendono di mira grandi organizzazioni governative in tutto il mondo.

Il 7 marzo, ha rilasciato di sicurezza per affrontare una critica identificata come CVE-2022-41328. Tale di sicurezza ha consentito agli aggressori di eseguire in codice remoto non autorizzato su un bersaglio.

redhotcyber.com/post/gli-explo

#threatactors #exploit #vulnerabilità #zeroday #fortios #fortinet #aggiornamenti #bug #sistema #redhotcyber #informationsecurity #ethicalhacking #dataprotection #cybersecurity #cybercrime #CyberSecurityAwareness #cybersecuritytraining #CyberSecurityNews #privacy #infosecurity

Last updated 2 years ago

securityaffairs · @securityaffairs
488 followers · 452 posts · Server infosec.exchange
LastBreach · @lastbreach
28 followers · 13 posts · Server infosec.exchange

in , FortiProxy und , wieder aktiv, auf Karlsruhe, Rastatt, Hospital Clínic Barcelona, und Rheinmetall, Festnahme von zwei Mitgliedern und startet -Kampagne gegen Frauen.

lastbreach.de/blog/die-weekly-

#schwachstellen #fortios #veeam #emotet #cyberangriffe #ransomware #iran #cyberspionage

Last updated 2 years ago

Opalsec :verified: · @Opalsec
175 followers · 85 posts · Server infosec.exchange

Happy Monday folks, I hope you had a restful weekend and managed to take a breather from all things cyber! Time to get back into it though, so let me give you hand - catch up on the week’s infosec news with the latest issue of our newsletter:

opalsec.substack.com/p/soc-gou

are back and are using…OneNote lures? ISO disk images? Malvertising? Nah – they’re sticking with tier tried and true TTPs – their Red Dawn maldoc template from last year; macro-enabled documents as lures, and null-byte padding to evade automated scanners.

We’ve highlighted a report on the Xenomorph Banking Trojan, which added support for targeting accounts of over 400 banks; automated bypassing of MFA-protected app logins, and a Session Token stealer module. With capabilities like these becoming the norm, is it time to take a closer look at the threat Mobile Malware could pose to enterprise networks?

North Korean hackers have demonstrated yet again that they’re tracking and integrating the latest techniques, and investing in malware development. A recent campaign saw eight new pieces of malware distributed throughout the kill chain, leveraging to deliver payloads and an in-memory dropper to abuse the technique and evade EDR solutions.

A joint investigation by and has unearthed a two-year campaign by Chinese actors, enabled through exploitation of unpatched SMA100 appliances and delivery of tailored payloads. A critical vulnerability reported by this week helps reinforce the point that perimeter devices need to be patched with urgency, as it’s a well-documented target for Chinese-affiliated actors.

is a novel malware targeting routers, sniffing network traffic and proxying C2 traffic to forward-deployed implants. TTPs employed in recent and campaigns are also worth taking note of, as is , a new malware family targeting specific web server applications to brute force logins and deploy an IRC bot for C2.

Those in Vulnerability Management should take particular note of the vulnerability, which appears trivial to exploit and actually delivers plaintext credentials to the attacker. CISA have also taken note of nearly 40k exploit attempts of a 2 year old code-exec-as-root vulnerability in the Cloud Foundation product in the last two months, so make sure you’re patched against it.

members have some excellent reading to look forward to, looking at HTTP request smuggling to harvest AD credentials and persisting with a MitM Exchange server, as well as a detailed post that examines ’s reflective loading capability;

The has some great tradecraft tips from @inversecos on DFIR, as well as tools to help scan websites for malicious objects, and to combat the new and well-established Raccoon Stealer.

Catch all this and much more in this week's newsletter:

opalsec.substack.com/p/soc-gou

#emotet #android #microsoft #intune #byovd #mandiant #sonicwall #fortinet #hiatusrat #draytek #batloader #qakbot #gobruteforcer #veeam #vmware #redteam #cobaltstrike #blueteam #azure #stealc #infostealer #infosec #cyber #news #cybernews #infosecnews #informationsecurity #cybersecurity #newsletter #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #soc #threatintel #threatintelligence #darkweb #mdm #dprk #fortios #FortiProxy

Last updated 2 years ago

Redhotcyber · @redhotcyber
417 followers · 644 posts · Server mastodon.bida.im

Fortinet: un nuovo difetto critico su FortiOS e FortiProxy potrebbe fornire ai malintenzionati l’accesso remoto

Il 7 marzo 2023,# Fortinet ha rilasciato 15 nuovi avvisi relativi alle nei suoi prodotti.

Tra tutti gli avvisi, ce nè uno di severtity bassa, otto medi, cinque alti e uno con valutazione critica. Questi avvisi riguardano , FortiAnalyzer, FortiManager, FortiPortal, FortiSwitch, , , FortiRecorder, FortiSOAR e .

redhotcyber.com/post/fortinet-

#psirt #vulnerabilità #fortios #FortiNAC #FortiProxy #FortiWeb #redhotcyber #informationsecurity #ethicalhacking #dataprotection #hacking #cybersecurity #cybercrime #CyberSecurityAwareness #cybersecuritytraining #CyberSecurityNews #privacy #infosecurity

Last updated 2 years ago

securityaffairs · @securityaffairs
477 followers · 432 posts · Server infosec.exchange
k3ym0 · @k3ym0
267 followers · 130 posts · Server infosec.exchange

❗​Critical (9.3 CVSS) CVE dropped for today. I recommend applying mitigations and updating your firewalls ASAP.

FortiGuard PSIRT: fortiguard.com/psirt/FG-IR-23-

Best Practices that mitigate this vuln:

  • Don't expose your admin interfaces to the internet
  • Use non-standard ports for your admin access (not 80/443)
  • Configure a Local In policy to limit IP addresses that can reach the admin interface (preferably to a set of jump hosts or Privileged Access Workstations)

#fortios #fortigate

Last updated 2 years ago

log4jm · @log4jmc
134 followers · 244 posts · Server infosec.exchange

New disclosure of Critical rating. CVE-2023-25610 affects various versions of . Source: fortiguard.com/psirt/FG-IR-22-

Affected Products

FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
FortiOS version 6.4.0 through 6.4.11
FortiOS 6.2 all versions

FortiProxy version 7.2.0 through 7.2.1
FortiProxy version 7.0.0 through 7.0.7
FortiProxy version 2.0.0 through 2.0.11
FortiProxy 1.2 all versions
FortiProxy 1.1 all versions

#fortinet #fortios #infosec #cve

Last updated 2 years ago

log4jm · @log4jmc
134 followers · 242 posts · Server infosec.exchange

New disclosure of Critical rating. CVE-2023-25610 affects various versions of . Source: fortiguard.com/psirt/FG-IR-22-

#fortinet #fortios

Last updated 2 years ago

log4jmc · @log4jmc
130 followers · 210 posts · Server infosec.exchange

Just noticed the new updates/advisories less than an hour before the end of the day when I'm supposed to be off tomorrow and Monday. I'm not taking any chances with my time and am going to patch quickly. By my count so far, 2 vulns rated High, 5 rated Medium, 1 Low

#fortinet #fortios

Last updated 3 years ago

Raphael · @0x3e4
32 followers · 97 posts · Server shitcoin.land

FortiOS 7.2.4 with a neat default behavior change:
"For new firewall policies with a deny action, set match-vip is enabled by default. When upgrading from a previous version, existing policy settings for match-vip are preserved."

#fortigate #fortios #fortinet

Last updated 3 years ago

Aida Akl · @AAKL
200 followers · 475 posts · Server noc.social

If you missed this:

Report: Cyberespionage threat actor exploits CVE-2022-42475 vulnerability techrepublic.com/article/mandi

#fortios #windows #linux #malware #cybersecurity

Last updated 3 years ago

Redhotcyber · @redhotcyber
360 followers · 401 posts · Server mastodon.bida.im

FortiOS SSL-VPN: la vulnerabilità 0-day sfruttata dagli hacker cinesi

Lo scorso autunno, gli hacker governativi cinesi hanno utilizzato una in come contro le agenzie europee e contro un fornitore di servizi gestiti () senza nome in Africa.

Gli specialisti di hanno affermato che gli aggressori hanno sfruttato la CVE-2022-42475 (un di heap buffer overflow in FortiOS ) che consente l’ di in modalità remota su dispositivi vulnerabili senza .

redhotcyber.com/post/fortios-s

#infosecurity #privacy #CyberSecurityNews #cybersecuritytraining #CyberSecurityAwareness #cybercrime #cybersecurity #hacking #dataprotection #ethicalhacking #informationsecurity #redhotcyber #autenticazione #codice #esecuzione #sslvpnd #mandiant #msp #governative #0day #attacco #SSLVPN #fortios #vulnerabilità

Last updated 3 years ago

My collection of resources and links I have found insightful and shared during week #03 of 2023.

Includes, but not only:

  • Exploits released for two Galaxy App Store vulnerabilities
  • Crims steal data on 40 million T-Mobile US customers
  • accounts breached in large-scale credential stuffing attack
  • Suspected Chinese Threat Actors Exploiting Vulnerability (CVE-2022–42475)
  • links data-wiping attack on news agency to Russian hackers
  • discloses new breach after employees got hacked
  • patches two critical remote code execution security flaws
  • How AI chatbot changes the game
  • LifeLock Password Manager Accounts Compromised

0x58.medium.com/my-shared-link

#infosec #samsung #paypal #fortios #ukraine #mailchimp #git #chatgpt #phishing #norton #cybersecurity #security

Last updated 3 years ago

Kody Kinzie · @skickar
238 followers · 52 posts · Server infosec.exchange

Government networks under attack by unknown hackers exploiting Fortinet FortiOS SSL-VPN zero-day vulnerability:
youtu.be/WWYiqOjQCg8
"

#cybersecurity #hacking #fortinet #fortios #sslvpn #zerodayvulnerability

Last updated 3 years ago