Fortiguard Labs

Latest News

signalreport-logo Threat Signal Report

Progress Telerik Report Server Authentication Bypass Vulnerability
Jul 08, 2024

What is the Vulnerability?Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability, allowing an attacker to bypass authentication and create rogue administrator...

signalreport-logo Threat Signal Report

Brain Cipher Ransomware Attack
Jun 28, 2024

What is the attack?A significant ransomware attack has struck Pusat Data Nasional (PDN), one of Indonesia’s government-owned national data centers. This incident involved threat actors encrypting...

signalreport-logo Threat Signal Report

Polyfill.io Supply Chain Attack
Jun 26, 2024

What is the attack?Over 100,000+ sites have been impacted by a supply chain attack involving the Polyfill.io service. Polyfill is a popular tool used for enhancing browser capabilities by hundreds...

outbreakalert-logo Outbreak Alert

Ivanti Connect Secure and Policy Secure Attack
Jun 25, 2024

Widespread exploitation of zero-day vulnerabilities affecting Ivanti Connect Secure and Policy Secure gateways underway.

outbreakalert-logo Outbreak Alert

PHP RCE Attack
Jun 12, 2024

FortiGuard Labs has observed significant level of exploitation attempts targeting the new PHP vulnerability. The TellYouThePass ransomware gang has been leveraging CVE-2024-4577, a remote code...

signalreport-logo Threat Signal Report

Oracle WebLogic Server Vulnerabilities (CVE-2023-21839, CVE-2017-3506)
Jun 04, 2024

What is the attack?A threat actor known as “8220 Gang” is seen exploiting two vulnerabilities in the Oracle WebLogic server: CVE-2017-3506, which allows remote OS command execution, and...

outbreakalert-logo Outbreak Alert

Check Point Quantum Security Gateways Information Disclosure Attack
May 27, 2024

Attackers exploit a zero-day vulnerability affecting Check Point Security Gateways to gain remote access. The vulnerability can allow attackers to read sensitive information on Check Point...

outbreakalert-logo Outbreak Alert

D-Link Multiple Devices Attack
May 24, 2024

Multiple D-link device vulnerabilities are being actively targeted. Many of the Routers and NAS devices are end-of-life (EOL) D-Link devices that do not have any patches available.

signalreport-logo Threat Signal Report

Genesis Market Malware Attack
May 22, 2024

 What is the attack?The FortiGuard Lab’s EDR team recently identified malware infection exhibiting strong similarities to the previously reported Genesis Market malicious campaign that was...

signalreport-logo Threat Signal Report

NextGen Healthcare Mirth Connect RCE (CVE-2023-43208, CVE-2023-37679)
May 21, 2024

 What is the vulnerability?NextGen Healthcare Mirth Connect is vulnerable to unauthenticated remote code execution (CVE-2023-43208) caused due to an incomplete patch of a Command Injection flaw...

outbreakalert-logo Outbreak Alert

Black Basta Ransomware
May 17, 2024

A new alert from CISA, the FBI, the Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) reveals that Black Basta affiliates have...

events-logo Publications

[Insomni'hack 2024] The Accessibility Abyss: Navigating Android Malware Waters
May 16, 2024

This talk is about Android malware which abuse the Accessibility Service API.

events-logo Publications

[BlackAlps 2022] You wont ever write Frida scripts again... (actually, yes, you will, it's just a fancy title)
May 16, 2024

This talk explains how to unpack Android malware using either static unpackers, or dynamic unpacking with Medusa.

outbreakalert-logo Outbreak Alert

ConnectWise ScreenConnect Attack
May 13, 2024

Threat actors including ransomware gangs are seen exploiting newly discovered critical flaws in remote monitoring and management software called ScreenConnect.

signalreport-logo Threat Signal Report

Google Chromium in Visuals Use-After-Free Vulnerability (CVE-2024-4671)
May 13, 2024

 What is the Vulnerability?A new zero-day vulnerability has recently been discovered in the Visuals component of Chrome, which is responsible for rendering and displaying web content. This “use...

signalreport-logo Threat Signal Report

Tinyproxy use-after-free Vulnerability (CVE-2023-49606)
May 07, 2024

 What is the vulnerability?A use-after-free vulnerability tagged as CVE-2023-49606 exists in Tinyproxy, a lightweight open-source HTTP proxy daemon. The threat actor may trigger this memory...

signalreport-logo Threat Signal Report

GitLab Password Reset Vulnerability (CVE-2023-7028)
May 02, 2024

What is the vulnerability?A critical vulnerability has been discovered in GitLab, a DevOps platform for managing software development lifecycle. A successful exploitation of the vulnerability may...

signalreport-logo Threat Signal Report

Ignite Realtime Openfire Path Traversal Vulnerability (CVE-2023-32315)
May 01, 2024

What is the vulnerability?The CVE-2023-32315 is a path traversal vulnerability that affects all Openfire versions since version 3.1.0. Successful exploitation of this vulnerability could allow...

signalreport-logo Threat Signal Report

Progress Telerik Report Server Authentication Bypass Vulnerability
Jul 08, 2024

What is the Vulnerability?Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability, allowing an attacker to bypass authentication and create rogue administrator...

signalreport-logo Threat Signal Report

Brain Cipher Ransomware Attack
Jun 28, 2024

What is the attack?A significant ransomware attack has struck Pusat Data Nasional (PDN), one of Indonesia’s government-owned national data centers. This incident involved threat actors encrypting...

signalreport-logo Threat Signal Report

Polyfill.io Supply Chain Attack
Jun 26, 2024

What is the attack?Over 100,000+ sites have been impacted by a supply chain attack involving the Polyfill.io service. Polyfill is a popular tool used for enhancing browser capabilities by hundreds...

outbreakalert-logo Outbreak Alert

Ivanti Connect Secure and Policy Secure Attack
Jun 25, 2024

Widespread exploitation of zero-day vulnerabilities affecting Ivanti Connect Secure and Policy Secure gateways underway.

outbreakalert-logo Outbreak Alert

PHP RCE Attack
Jun 12, 2024

FortiGuard Labs has observed significant level of exploitation attempts targeting the new PHP vulnerability. The TellYouThePass ransomware gang has been leveraging CVE-2024-4577, a remote code...

signalreport-logo Threat Signal Report

Oracle WebLogic Server Vulnerabilities (CVE-2023-21839, CVE-2017-3506)
Jun 04, 2024

What is the attack?A threat actor known as “8220 Gang” is seen exploiting two vulnerabilities in the Oracle WebLogic server: CVE-2017-3506, which allows remote OS command execution, and...

outbreakalert-logo Outbreak Alert

Check Point Quantum Security Gateways Information Disclosure Attack
May 27, 2024

Attackers exploit a zero-day vulnerability affecting Check Point Security Gateways to gain remote access. The vulnerability can allow attackers to read sensitive information on Check Point...

outbreakalert-logo Outbreak Alert

D-Link Multiple Devices Attack
May 24, 2024

Multiple D-link device vulnerabilities are being actively targeted. Many of the Routers and NAS devices are end-of-life (EOL) D-Link devices that do not have any patches available.

signalreport-logo Threat Signal Report

Genesis Market Malware Attack
May 22, 2024

 What is the attack?The FortiGuard Lab’s EDR team recently identified malware infection exhibiting strong similarities to the previously reported Genesis Market malicious campaign that was...

signalreport-logo Threat Signal Report

NextGen Healthcare Mirth Connect RCE (CVE-2023-43208, CVE-2023-37679)
May 21, 2024

 What is the vulnerability?NextGen Healthcare Mirth Connect is vulnerable to unauthenticated remote code execution (CVE-2023-43208) caused due to an incomplete patch of a Command Injection flaw...

outbreakalert-logo Outbreak Alert

Black Basta Ransomware
May 17, 2024

A new alert from CISA, the FBI, the Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) reveals that Black Basta affiliates have...

events-logo Publications

[Insomni'hack 2024] The Accessibility Abyss: Navigating Android Malware Waters
May 16, 2024

This talk is about Android malware which abuse the Accessibility Service API.

events-logo Publications

[BlackAlps 2022] You wont ever write Frida scripts again... (actually, yes, you will, it's just a fancy title)
May 16, 2024

This talk explains how to unpack Android malware using either static unpackers, or dynamic unpacking with Medusa.

outbreakalert-logo Outbreak Alert

ConnectWise ScreenConnect Attack
May 13, 2024

Threat actors including ransomware gangs are seen exploiting newly discovered critical flaws in remote monitoring and management software called ScreenConnect.

signalreport-logo Threat Signal Report

Google Chromium in Visuals Use-After-Free Vulnerability (CVE-2024-4671)
May 13, 2024

 What is the Vulnerability?A new zero-day vulnerability has recently been discovered in the Visuals component of Chrome, which is responsible for rendering and displaying web content. This “use...

signalreport-logo Threat Signal Report

Tinyproxy use-after-free Vulnerability (CVE-2023-49606)
May 07, 2024

 What is the vulnerability?A use-after-free vulnerability tagged as CVE-2023-49606 exists in Tinyproxy, a lightweight open-source HTTP proxy daemon. The threat actor may trigger this memory...

signalreport-logo Threat Signal Report

GitLab Password Reset Vulnerability (CVE-2023-7028)
May 02, 2024

What is the vulnerability?A critical vulnerability has been discovered in GitLab, a DevOps platform for managing software development lifecycle. A successful exploitation of the vulnerability may...

signalreport-logo Threat Signal Report

Ignite Realtime Openfire Path Traversal Vulnerability (CVE-2023-32315)
May 01, 2024

What is the vulnerability?The CVE-2023-32315 is a path traversal vulnerability that affects all Openfire versions since version 3.1.0. Successful exploitation of this vulnerability could allow...

signalreport-logo Threat Signal Report

Progress Telerik Report Server Authentication Bypass Vulnerability
Jul 08, 2024

What is the Vulnerability?Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability, allowing an attacker to bypass authentication and create rogue administrator...

signalreport-logo Threat Signal Report

Brain Cipher Ransomware Attack
Jun 28, 2024

What is the attack?A significant ransomware attack has struck Pusat Data Nasional (PDN), one of Indonesia’s government-owned national data centers. This incident involved threat actors encrypting...

signalreport-logo Threat Signal Report

Polyfill.io Supply Chain Attack
Jun 26, 2024

What is the attack?Over 100,000+ sites have been impacted by a supply chain attack involving the Polyfill.io service. Polyfill is a popular tool used for enhancing browser capabilities by hundreds...

outbreakalert-logo Outbreak Alert

Ivanti Connect Secure and Policy Secure Attack
Jun 25, 2024

Widespread exploitation of zero-day vulnerabilities affecting Ivanti Connect Secure and Policy Secure gateways underway.

outbreakalert-logo Outbreak Alert

PHP RCE Attack
Jun 12, 2024

FortiGuard Labs has observed significant level of exploitation attempts targeting the new PHP vulnerability. The TellYouThePass ransomware gang has been leveraging CVE-2024-4577, a remote code...

signalreport-logo Threat Signal Report

Oracle WebLogic Server Vulnerabilities (CVE-2023-21839, CVE-2017-3506)
Jun 04, 2024

What is the attack?A threat actor known as “8220 Gang” is seen exploiting two vulnerabilities in the Oracle WebLogic server: CVE-2017-3506, which allows remote OS command execution, and...

outbreakalert-logo Outbreak Alert

Check Point Quantum Security Gateways Information Disclosure Attack
May 27, 2024

Attackers exploit a zero-day vulnerability affecting Check Point Security Gateways to gain remote access. The vulnerability can allow attackers to read sensitive information on Check Point...

outbreakalert-logo Outbreak Alert

D-Link Multiple Devices Attack
May 24, 2024

Multiple D-link device vulnerabilities are being actively targeted. Many of the Routers and NAS devices are end-of-life (EOL) D-Link devices that do not have any patches available.

signalreport-logo Threat Signal Report

Genesis Market Malware Attack
May 22, 2024

 What is the attack?The FortiGuard Lab’s EDR team recently identified malware infection exhibiting strong similarities to the previously reported Genesis Market malicious campaign that was...

signalreport-logo Threat Signal Report

NextGen Healthcare Mirth Connect RCE (CVE-2023-43208, CVE-2023-37679)
May 21, 2024

 What is the vulnerability?NextGen Healthcare Mirth Connect is vulnerable to unauthenticated remote code execution (CVE-2023-43208) caused due to an incomplete patch of a Command Injection flaw...

outbreakalert-logo Outbreak Alert

Black Basta Ransomware
May 17, 2024

A new alert from CISA, the FBI, the Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) reveals that Black Basta affiliates have...

events-logo Publications

[Insomni'hack 2024] The Accessibility Abyss: Navigating Android Malware Waters
May 16, 2024

This talk is about Android malware which abuse the Accessibility Service API.

events-logo Publications

[BlackAlps 2022] You wont ever write Frida scripts again... (actually, yes, you will, it's just a fancy title)
May 16, 2024

This talk explains how to unpack Android malware using either static unpackers, or dynamic unpacking with Medusa.

outbreakalert-logo Outbreak Alert

ConnectWise ScreenConnect Attack
May 13, 2024

Threat actors including ransomware gangs are seen exploiting newly discovered critical flaws in remote monitoring and management software called ScreenConnect.

signalreport-logo Threat Signal Report

Google Chromium in Visuals Use-After-Free Vulnerability (CVE-2024-4671)
May 13, 2024

 What is the Vulnerability?A new zero-day vulnerability has recently been discovered in the Visuals component of Chrome, which is responsible for rendering and displaying web content. This “use...

signalreport-logo Threat Signal Report

Tinyproxy use-after-free Vulnerability (CVE-2023-49606)
May 07, 2024

 What is the vulnerability?A use-after-free vulnerability tagged as CVE-2023-49606 exists in Tinyproxy, a lightweight open-source HTTP proxy daemon. The threat actor may trigger this memory...

signalreport-logo Threat Signal Report

GitLab Password Reset Vulnerability (CVE-2023-7028)
May 02, 2024

What is the vulnerability?A critical vulnerability has been discovered in GitLab, a DevOps platform for managing software development lifecycle. A successful exploitation of the vulnerability may...

signalreport-logo Threat Signal Report

Ignite Realtime Openfire Path Traversal Vulnerability (CVE-2023-32315)
May 01, 2024

What is the vulnerability?The CVE-2023-32315 is a path traversal vulnerability that affects all Openfire versions since version 3.1.0. Successful exploitation of this vulnerability could allow...

Certifications

  • av comparatives logo
  • common criteria logo
  • nss labs logo
  • vb logo
  • mitre logo