<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Fortinet Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Fortinet.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>FortiBleed Emergency: 74,000 Fortinet Logins Exposed</title><link>https://youtube.com/watch?v=fwnEN-OIH_w</link><guid isPermaLink="false">cst-2916</guid><description>A security issue called FortiBleed has resulted in the exposure of approximately 74,000 Fortinet login credentials. The incident appears to affect Fortinet products and services used by organizations worldwide.</description><pubDate>Tue, 21 Jul 2026 13:21:42 GMT</pubDate></item><item><title>CISA urges immediate action on actively exploited Fortinet flaws</title><link>https://bleepingcomputer.com/news/security/cisa-warns-feds-to-patch-exploited-fortinet-fortisandbox-flaws-by-sunday</link><guid isPermaLink="false">cst-2735</guid><description>The Cybersecurity and Infrastructure Security Agency (CISA) issued a directive requiring federal agencies to patch two actively exploited vulnerabilities affecting Fortinet FortiSandbox. The vulnerabilities are being leveraged in active attacks and warrant urgent remediation.</description><pubDate>Fri, 17 Jul 2026 07:03:33 GMT</pubDate></item><item><title>Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow</title><link>https://securityweek.com/vulnerabilities-patched-by-fortinet-ivanti-servicenow</link><guid isPermaLink="false">cst-2576</guid><description>ServiceNow, Fortinet, and Ivanti each released patches for security vulnerabilities affecting their platforms. A critical vulnerability in ServiceNow's AI platform could allow remote attackers to execute arbitrary code.</description><pubDate>Wed, 15 Jul 2026 11:02:57 GMT</pubDate></item><item><title>Fortinet adds AI controls and data loss prevention to FortiEndpoint</title><link>https://helpnetsecurity.com/2026/07/15/fortinet-fortiai-assist</link><guid isPermaLink="false">cst-2560</guid><description>Fortinet announced new AI visibility, control, and data loss prevention capabilities integrated into its FortiEndpoint unified endpoint platform. The additions include endpoint risk scoring, AI-assisted security operations, and features to govern AI usage and reduce sensitive data exposure across distributed environments.</description><pubDate>Wed, 15 Jul 2026 07:47:57 GMT</pubDate></item><item><title>FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations</title><link>https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html</link><guid isPermaLink="false">cst-38</guid><description>Security researchers have linked the FortiBleed credential theft campaign to infrastructure associated with both INC and Lynx ransomware operations, with evidence showing operators managing negotiation panels for both groups. The stolen FortiGate credentials appear to be harvested for follow-on ransomware deployment rather than standalone credential trafficking.</description><pubDate>Thu, 02 Jul 2026 08:00:49 GMT</pubDate></item><item><title>Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures</title><link>https://thehackernews.com/2026/07/ousaban-banking-trojan-targets-iberian.html</link><guid isPermaLink="false">cst-45</guid><description>Fortinet researchers identified a campaign in May 2026 targeting banking users in Spain and Portugal with Ousaban, a Brazilian banking trojan distributed through phishing emails containing fake PDF files. The malware verifies the victim's geographic location and conceals its payload within image files to steal banking credentials.</description><pubDate>Wed, 01 Jul 2026 15:26:55 GMT</pubDate></item><item><title>How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it.</title><link>https://tenable.com/blog/how-much-cyber-risk-does-ai-create-for-organizations-457-million-security-issues-heres-what</link><guid isPermaLink="false">cst-382</guid><description>Tenable detected 457 million AI-related security issues across over 7,000 organizations during a 30-day period, averaging 62,000 exposures per organization. These issues stem primarily from misconfigurations and unmanaged dependencies rather than traditional CVEs, and organizations continue to struggle with patching known vulnerabilities, with median time-to-patch increasing to 43 days. Security teams need to shift from CVE-focused approaches to comprehensive exposure management using automated workflows and AI-driven tools to address the full attack surface.</description><pubDate>Wed, 24 Jun 2026 13:00:00 GMT</pubDate></item><item><title>An update on FortiBleed — what’s happening with victim orgs</title><link>https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4?source=rss----8343faddf0ec---4</link><guid isPermaLink="false">cst-583</guid><description>FortiBleed exposed Fortinet firewall administrator credentials at scale after an attacker gained access to tens of thousands of devices, exported configurations, and cracked password hashes using rented GPU compute resources. The attacker's infrastructure left evidence in an open directory, revealing that approximately 1,000 organizations were directly compromised, though credential theft occurred across tens of thousands of devices, with stolen FortiVPN credentials now being resold on underground forums. Many victim organizations show evidence of configuration exports in their logs over the past month from multiple IP addresses.</description><pubDate>Fri, 19 Jun 2026 19:02:25 GMT</pubDate></item><item><title>Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways</title><link>https://ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways</link><guid isPermaLink="false">cst-286</guid><description>The UK National Cyber Security Centre (NCSC) has issued guidance in response to a global campaign targeting Fortinet firewalls and VPN (Virtual Private Network) gateways. Organizations running these devices are being advised to take immediate action to protect their infrastructure.</description><pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate></item><item><title>Massive breach spills credentials for thousands of sensitive networks</title><link>https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks</link><guid isPermaLink="false">cst-431</guid><description>Researchers discovered a massive breach affecting approximately 74,000 Fortinet firewalls across more than 21,000 organizations in 194 countries, with plaintext credentials exposed online. Russian-speaking attackers gained access to sensitive networks at major organizations including Oracle, Chevron, Lenovo, Federal Express, and NATO defense contractors. In many cases, threat actors leveraged the compromised devices to access centralized authentication systems such as Active Directory and Radius servers.</description><pubDate>Wed, 17 Jun 2026 19:54:31 GMT</pubDate></item><item><title>Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world</title><link>https://techcrunch.com/2026/06/17/cybercriminals-allegedly-hacked-tens-of-thousands-of-fortinet-firewalls-used-by-major-companies-all-over-the-world</link><guid isPermaLink="false">cst-480</guid><description>Cybercriminals speaking Russian are allegedly exploiting Fortinet firewalls and VPNs at major companies worldwide using previously disclosed credentials. The attacks target multiple organizations that have not updated their default or known passwords on these network appliances.</description><pubDate>Wed, 17 Jun 2026 18:20:06 GMT</pubDate></item><item><title>FortiBleed — 75k Fortinet firewalls have admin passwords cracked</title><link>https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8?source=rss----8343faddf0ec---4</link><guid isPermaLink="false">cst-584</guid><description>Approximately 75,000 Fortinet firewall admin passwords were exposed in a recent data leak discovered by Hunt Intelligence Inc, with the plaintext credentials extracted from device configuration exports. The compromised devices represent roughly 50% of all internet-facing Fortinet firewalls, and most remain online and accessible. The source and method of the breach remain unclear, though it may involve known CVEs or a previously unknown vulnerability.</description><pubDate>Wed, 17 Jun 2026 14:13:44 GMT</pubDate></item><item><title>May 2026 CVE Landscape</title><link>https://recordedfuture.com/blog/may-2026-cve-landscape</link><guid isPermaLink="false">cst-1953</guid><description>In May 2026, Insikt Group identified 41 high-impact vulnerabilities requiring prioritized remediation, representing an 11% increase from April. These vulnerabilities affected 20 vendors, with 21 included in CISA's Known Exploited Vulnerabilities catalog, 19 detected via honeypot data, and one reported by a vendor. Notably, 12 vulnerabilities enabled remote code execution, public proof-of-concept exploits were available for 32 of them, and five were first disclosed between 2008 and 2010, demonstrating continued exploitation of long-standing weaknesses.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Nightmare-Eclipse Tooling Seen in Real-World Intrusion</title><link>https://huntress.com/blog/nightmare-eclipse-intrusion</link><guid isPermaLink="false">cst-711</guid><description>Huntress detected active use of Nightmare-Eclipse attack tools (BlueHammer, RedSun, and UnDefend) during a real-world intrusion that began with a compromised FortiGate VPN, followed by reconnaissance and likely data tunneling activity. The incident demonstrates operational deployment of this toolset against production environments.</description><pubDate>Mon, 20 Apr 2026 18:00:00 GMT</pubDate></item><item><title>Risky Bulletin: AI-driven hacking campaign breaches 600+ Fortinet devices</title><link>https://risky.biz/risky-bulletin-ai-driven-hacking-campaign-breaches-600-fortinet-devices</link><guid isPermaLink="false">cst-234</guid><description>A Russian-speaking threat actor used commercial AI toolkits to compromise over 600 Fortinet FortiGate firewalls starting in January by targeting exposed management ports protected only by weak passwords without multi-factor authentication (MFA). The campaign did not rely on zero-day or legacy vulnerabilities but instead exploited basic security configuration weaknesses. AWS security researchers documented the campaign and its techniques.</description><pubDate>Mon, 23 Feb 2026 00:51:20 GMT</pubDate></item><item><title>Risky Bulletin: Improperly patched bug exploited again in Fortinet firewalls</title><link>https://risky.biz/risky-bulletin-improperly-patched-bug-exploited-again-in-fortinet-firewalls</link><guid isPermaLink="false">cst-250</guid><description>Fortinet FortiGate firewalls are being actively exploited through CVE-2025-59718, a vulnerability that was inadequately patched in previous updates. Attackers are bypassing SSO authentication using generic usernames, provisioning administrative accounts, and exfiltrating device configurations. Fortinet has acknowledged the new exploitation method to select customers via private communications.</description><pubDate>Thu, 22 Jan 2026 22:44:13 GMT</pubDate></item><item><title>FortiWeb CVE‑2025‑64446: What We’re Seeing in the Wild</title><link>https://greynoise.io/blog/fortiweb-cve-2025-64446</link><guid isPermaLink="false">cst-1874</guid><description>GreyNoise has detected active exploitation of CVE-2025-64446, a critical path-traversal vulnerability in Fortinet FortiWeb that allows unauthenticated attackers to execute administrative commands on affected appliances. The flaw is being actively exploited in the wild against internet-facing FortiWeb instances.</description><pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate></item><item><title>A Coordinated Brute Force Campaign Targets Fortinet SSL VPN</title><link>https://greynoise.io/blog/vulnerability-fortinet-vpn-bruteforce-spike</link><guid isPermaLink="false">cst-1890</guid><description>GreyNoise detected a coordinated brute force campaign against Fortinet SSL VPN on August 3rd, 2025, with over 780 unique IPs engaging in attack traffic. This represents the highest single-day volume of such activity observed in recent months.</description><pubDate>Tue, 12 Aug 2025 00:00:00 GMT</pubDate></item><item><title>CISA Flags Actively Exploited Flaws in AMI, D-Link, and Fortinet Devices</title><link>https://halcyon.ai/blog/cisa-flags-actively-exploited-flaws-in-ami-d-link-and-fortinet-devices</link><guid isPermaLink="false">cst-2068</guid><description>CISA has identified actively exploited vulnerabilities affecting AMI, D-Link, and Fortinet devices. These flaws are being leveraged in real-world attacks and require immediate patching.</description><pubDate>Mon, 30 Jun 2025 08:52:19 GMT</pubDate></item><item><title>Hackers Actively Exploiting Fortinet Firewalls: Real-Time Insights from GreyNoise</title><link>https://greynoise.io/blog/hackers-actively-exploiting-fortinet-firewalls-real-time-insights-from-greynoise</link><guid isPermaLink="false">cst-1922</guid><description>Attackers are actively exploiting Fortinet FortiGate firewalls vulnerable to CVE-2022-40684, with real-time threat intelligence available from GreyNoise. The article provides insights to help defenders understand and respond to ongoing exploitation attempts.</description><pubDate>Tue, 28 Jan 2025 00:00:00 GMT</pubDate></item><item><title>BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA</title><link>https://volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata</link><guid isPermaLink="false">cst-2111</guid><description>Volexity discovered a zero-day credential disclosure vulnerability in Fortinet's FortiClient Windows VPN client in July 2024, exploited by the Chinese state-affiliated threat actor BrazenBamboo through its modular malware DEEPDATA. The vulnerability allows extraction of VPN credentials from the VPN client's process memory, and Fortinet published a public acknowledgement with patching guidance in December 2024. BrazenBamboo also operates related malware families including LIGHTSPY and DEEPPOST for information gathering and file exfiltration.</description><pubDate>Fri, 15 Nov 2024 14:50:18 GMT</pubDate></item><item><title>February Fortinet Advisory: everything you need to know</title><link>https://wiz.io/blog/critical-rce-vulnerabilities-in-fortios-cve-2024-21762-cve-2024-23113</link><guid isPermaLink="false">cst-1628</guid><description>Fortinet released advisory guidance for two critical remote code execution (RCE) vulnerabilities affecting FortiOS and FortiProxy, identified as CVE-2024-21762 and CVE-2024-23113. The advisory includes detection and mitigation steps, with Fortinet recommending urgent patching to address these issues.</description><pubDate>Mon, 12 Feb 2024 13:53:10 GMT</pubDate></item><item><title>Wiz and Fortinet announce partnership to deliver cloud-native security protection</title><link>https://wiz.io/blog/wiz-and-fortinet-announce-partnership-to-deliver-cloud-native-security-protection</link><guid isPermaLink="false">cst-1684</guid><description>Wiz and Fortinet have partnered to integrate cloud security capabilities with network firewall functionality, allowing customers to detect, prioritize, and remediate public cloud exposures using both platforms together.</description><pubDate>Mon, 11 Sep 2023 12:55:01 GMT</pubDate></item></channel></rss>