{"rows":[{"id":"e375cdbee41ac09ea503a5043108fb990903e1cf","sourceId":"gbhackers","url":"https://gbhackers.com/best-server-security-compared-2/","title":"12 Best Server Security Solutions Compared (2026): Features & Pricing","author":"Kavichselvan","publishedAt":1789111441000,"fetchedAt":1789112214507,"feedSummary":"Quick Answer: CrowdStrike and SentinelOne lead server EDR; Trend Micro Deep Security owns virtual patching for unpatchable estates; Microsoft Defender for Servers is the per-resource anchor for Azure/hybrid; Bitdefender and ESET deliver efficacy at value. Server pricing runs per server/workload always confirm Linux feature parity. Servers are where ransomware crews head after the first phish: […]\nThe post 12 Best Server Security Solutions Compared (2026): Features & Pricing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.","contentStatus":"ok","imageUrl":"https://gbhackers.com/wp-content/uploads/2026/08/Best-Server-Security-Solutions-1.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789112214507,"category":"industry","severity":"info","importance":14,"tldr":"GBHackers ranks 12 server security solutions for 2026, naming CrowdStrike and SentinelOne as server EDR leaders and Trend Micro Deep Security top for virtual patching.","summary":"The guide scores 12 server security platforms across five weighted criteria, with detection and response depth and Linux parity weighted 25% each. CrowdStrike and SentinelOne lead server EDR, Trend Micro Deep Security is highlighted for virtual patching of unpatchable estates, and Microsoft Defender for Servers is noted for Azure and hybrid economics. It is an editorial assessment comparing features and pricing models rather than a lab test.","keyPoints":["CrowdStrike and SentinelOne top the server EDR category; Trend Micro leads on virtual patching and workload controls.","Uptycs is ranked best for Linux-heavy, engineering-led estates via an osquery-based data model."],"tags":["server-security","edr","virtual-patching","workload-protection","buyer-guide","crowdstrike","sentinelone","trend-micro"],"entities":{"malware":[],"vendors":["CrowdStrike","SentinelOne","Trend Micro","Microsoft","Sophos","Bitdefender","Palo Alto Networks","Uptycs","Cisco","Fortinet"],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.85,"clusterId":"39e2b98ad279939239bf42b0ca76c8a18baabca3","extra":{"hint":null,"source_weight":0.7},"sourceName":"GBHackers","sourceHomepage":"https://gbhackers.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"8b64c3ba7936d5568655126d16c780a2e9d8ef8b","sourceId":"cybersecuritynews","url":"https://cybersecuritynews.com/best-cspm-tools/","title":"Top 10 Best Cloud Security Posture Management (CSPM) Tools in 2026","author":"Kavichselvan","publishedAt":1789110659000,"fetchedAt":1789111014464,"feedSummary":"CSPM finds the cloud misconfigurations that cause most cloud breaches public buckets, permissive IAM, exposed databases continuously, across accounts and providers. Wiz still sets the pace on agentless visibility and attack-path context, Microsoft Defender for Cloud wins Azure-centric economics, and the market’s biggest story is corporate: Google’s agreement to acquire Wiz for approximately $32 billion, […]\nThe post Top 10 Best Cloud Security Posture Management (CSPM) Tools in 2026 appeared first on Cyber Security News.","contentStatus":"ok","imageUrl":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Best-Cloud-Security-Posture-Management-CSPM-Tools-.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789111014464,"category":"industry","severity":"info","importance":14,"tldr":"2026 CSPM comparison ranks Wiz atop cloud posture tools and recaps Google's pending roughly $32 billion acquisition of Wiz.","summary":"An editorial guide rates ten cloud security posture management (CSPM) tools, with Wiz ranked first for agentless visibility and attack-path context, Microsoft Defender for Cloud highlighted for Azure-centric economics, and Palo Alto Prisma Cloud noted for the broadest code-to-cloud module set. The article's biggest market note is Google's agreement to acquire Wiz for approximately $32 billion, described as the largest deal in security history, still progressing through regulatory review. It advises buyers to include roadmap-protection language in multi-year commitments and to press on multicloud neutrality post-close.","keyPoints":["Wiz ranked the reference CSPM for agentless scanning and security graph context.","Microsoft Defender for Cloud positioned as best value for Azure-heavy estates.","Google's ~$32 billion Wiz acquisition remains the sector's defining corporate story.","Orca, CrowdStrike, Check Point, Tenable, Fortinet (Lacework), Trend Micro, Rapid7 also reviewed."],"tags":["cspm","cloud-security","cnapp","wiz","google","agentless","posture-management"],"entities":{"malware":[],"vendors":["Wiz","Palo Alto Networks","Microsoft","Orca Security","CrowdStrike","Check Point","Tenable","Fortinet","Trend Micro","Rapid7"],"victims":[],"products":["Wiz","Microsoft Defender for Cloud","Prisma Cloud","Falcon Cloud Security","CloudGuard"],"ai_models":[],"countries":[],"organizations":["Google","Wiz","Palo Alto Networks","Microsoft","Orca Security"],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.9,"clusterId":"8b64c3ba7936d5568655126d16c780a2e9d8ef8b","extra":{"hint":null,"source_weight":0.7},"sourceName":"Cyber Security News","sourceHomepage":"https://cybersecuritynews.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"84683c5b3f9fb6521196c8f84006da04e19fc6f2","sourceId":"securityaffairs","url":"https://securityaffairs.com/198850/security/u-s-cisa-adds-cisco-google-chromium-v8-fortinet-and-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html","title":"U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog","author":"Pierluigi Paganini","publishedAt":1789066641000,"fetchedAt":1789070212071,"feedSummary":"U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20079 (CVSS score of 10.0) is an authentication bypass issue. The flaw resides in Cisco Secure […]","contentStatus":"ok","imageUrl":"https://securityaffairs.com/wp-content/uploads/2020/07/CISA.jpeg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789070212071,"category":"exploit","severity":"critical","importance":84,"tldr":"CISA added actively exploited Cisco FMC, Chrome V8, Fortinet and Citrix NetScaler flaws to its KEV catalog, ordering federal patching by September 12.","summary":"CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. CVE-2026-20079 (CVSS 10.0) is an unauthenticated authentication bypass in Cisco Secure Firewall Management Center's web interface enabling script execution and potential root access. CVE-2026-87491 (CVSS 8.8) is an out-of-bounds write in Chrome's V8 engine — the seventh actively exploited Chrome zero-day of 2026 — fixed in Chrome 153.0.8010.36. CVE-2025-25249 (CVSS 8.1) is a heap-based buffer overflow in FortiOS/FortiSwitchManager's cw_acd daemon being exploited with the PivotC2 RAT, and CVE-2026-19490 (CVSS 9.3) is a NetScaler SAML HTTP-Redirect authentication bypass; federal agencies must patch by September 12, 2026.","keyPoints":["CVE-2026-20079 (CVSS 10.0): unauthenticated Cisco Secure FMC web-interface auth bypass enabling root access.","CVE-2026-87491 (CVSS 8.8): V8 out-of-bounds write, seventh actively exploited Chrome zero-day of 2026.","CVE-2025-25249 (CVSS 8.1): FortiOS cw_acd heap overflow, exploited with PivotC2 RAT on FortiGate devices.","CVE-2026-19490 (CVSS 9.3): Citrix NetScaler SAML HTTP-Redirect binding authentication bypass.","Federal civilian agencies must patch KEV entries by September 12, 2026."],"tags":["cisa","kev","cisco","chrome","fortinet","citrix","netscaler","zero-day"],"entities":{"malware":["PivotC2"],"vendors":["Cisco","Google","Fortinet","Citrix"],"victims":[],"products":["Chrome","FortiOS","FortiSwitchManager","NetScaler ADC","NetScaler Gateway","Secure Firewall Management Center"],"ai_models":[],"countries":["US"],"organizations":["CISA"],"threat_actors":[]},"cves":["CVE-2025-25249","CVE-2026-19490","CVE-2026-87491","CVE-2026-20079"],"inTheWild":true,"confidence":0.95,"clusterId":"91c160320310ca1b156d2c2449c074390263f265","extra":{"hint":null,"related":[],"related_at":1789070212071,"source_weight":1,"related_provider":"bing"},"sourceName":"Security Affairs","sourceHomepage":"https://securityaffairs.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"f1d62f9bfba1896e06677cf6b4a73dff8a138daa","sourceId":"securityweek","url":"https://www.securityweek.com/cybersecurity-ma-roundup-33-deals-announced-in-august-2026/","title":"Cybersecurity M&A Roundup: 33 Deals Announced in August 2026","author":"Eduard Kovacs","publishedAt":1789056898000,"fetchedAt":1789057011326,"feedSummary":"Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.\nThe post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek.","contentStatus":"ok","imageUrl":"https://www.securityweek.com/wp-content/uploads/2026/02/MA-mergers-and-acquisitions.jpeg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789057011326,"category":"industry","severity":"info","importance":45,"tldr":"SecurityWeek tallied 33 cybersecurity M&A deals announced in August 2026, headlined by Visa's $2.4B BioCatch buy and Munich Re's $575M At-Bay acquisition.","summary":"Thirty-three cybersecurity M&A deals were announced in August 2026. The largest include Visa acquiring fraud-detection firm BioCatch for $2.4 billion in cash and Munich Re buying cyber insurtech At-Bay for $575 million through its HSB unit. Fortinet acquired AI security company Virtue AI, Palo Alto Networks bought agentic workflow platform Console, Cribl acquired AI-native SOC startup Radiant Security, and Deel bought deepfake-detection firm Clarity for a reported $40-50 million. Brinqa, Datavault AI, Echo, and Kiteworks also announced acquisitions.","keyPoints":["Visa is buying fraud prevention firm BioCatch for $2.4 billion in cash","Munich Re to acquire cyber insurtech At-Bay for $575 million via its HSB unit","Fortinet acquired Virtue AI for agentic system red teaming, agent protection, and guardrails","Deel acquired deepfake-detection firm Clarity for a reported $40-50 million","Palo Alto Networks bought Console to deepen agentic capabilities of its Cortex platform"],"tags":["ma","acquisitions","industry","visa","fortinet","palo-alto-networks","cribl","munich-re"],"entities":{"malware":[],"vendors":["Visa","BioCatch","Munich Re","At-Bay","Fortinet","Virtue AI","Palo Alto Networks","Console","Cribl","Radiant Security"],"victims":[],"products":["Cortex","CTEM"],"ai_models":[],"countries":["Japan","Israel"],"organizations":["SecurityWeek","HSB"],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.97,"clusterId":"f1d62f9bfba1896e06677cf6b4a73dff8a138daa","extra":{"hint":null,"source_weight":1.1},"sourceName":"SecurityWeek","sourceHomepage":"https://www.securityweek.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"84c9494d4736044869de17270abe0633a1d271ad","sourceId":"cybersecuritynews","url":"https://cybersecuritynews.com/fortinet-heap-based-buffer-overflow/","title":"CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks","author":"Abinaya","publishedAt":1789039565000,"fetchedAt":1789040210443,"feedSummary":"The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet vulnerability, tracked as CVE-2025-25249, to its Known Exploited Vulnerabilities catalog after confirming evidence of active exploitation. The flaw affects FortiOS, FortiSwitchManager, and FortiSASE products. It could allow attackers to execute unauthorized code or commands by sending specially crafted packets. CVE-2025-25249 is a heap-based […]\nThe post CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks appeared first on Cyber Security News.","contentStatus":"ok","imageUrl":"https://cybersecuritynews.com/wp-content/uploads/2026/09/CISA-Warns-of-Fortinet-Heap-based-Buffer-Overflow-Flaw-Exploited-in-Attacks-.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789040210443,"category":"exploit","severity":"critical","importance":85,"tldr":"CISA added actively exploited Fortinet CVE-2025-25249, a critical heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, to its KEV catalog.","summary":"CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) allowing unauthorized code execution by sending specially crafted packets. CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026, with a September 12 remediation deadline for federal agencies under BOD 26-04 and mandatory forensic triage of affected environments. Internet-facing Fortinet firewalls and SASE platforms are a likely foothold for credential theft, persistence, and lateral movement; ransomware use is currently listed as unknown.","keyPoints":["CVE-2025-25249 heap overflow enables code execution via crafted packets","KEV addition Sept 9, 2026; federal patch deadline Sept 12 under BOD 26-04","CISA requires forensic triage, not just routine patching","Prioritize internet-exposed FortiOS, FortiSwitchManager, FortiSASE assets"],"tags":["fortinet","fortios","fortisase","kev","cisa","buffer-overflow","exploitation"],"entities":{"malware":[],"vendors":["Fortinet","CISA"],"victims":[],"products":["FortiOS","FortiSwitchManager","FortiSASE"],"ai_models":[],"countries":["United States"],"organizations":["CISA"],"threat_actors":[]},"cves":["CVE-2025-25249"],"inTheWild":true,"confidence":0.9,"clusterId":"bdff752a92d12e85687c870587904c88e9714bef","extra":{"hint":null,"related":[],"related_at":1789040210443,"source_weight":0.7,"related_provider":"bing"},"sourceName":"Cyber Security News","sourceHomepage":"https://cybersecuritynews.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"11d7a096bf9c05eb56ed290dd4114239bf09a4de","sourceId":"thehackernews","url":"https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html","title":"CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline","author":"info@thehackernews.com (The Hacker News)","publishedAt":1789036606000,"fetchedAt":1789040210443,"feedSummary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.\nThe vulnerabilities are listed below -\nCVE-2026-20079 (CVSS score: 10.0) - An authentication","contentStatus":"ok","imageUrl":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7j6Sm8OqDeYzrbb5faLBuDOc0zIMlvfjiKbn1aCMpx_2iBl6gb3HhJhpbqU8SPajHUClJEXUwnFbY1DcubmzWeVaWCyGcHkw45rCYqU_4IFO_g4OwdyNrTFFK3l3YsXwfOWQj2QtW3UTeglKmyRJ4GvbVKMxLTByMgeZ7E0WWpxpi50qie2lx9DbCY9rr/s1600/cisa-list.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789040210443,"category":"exploit","severity":"high","importance":85,"tldr":"CISA adds actively exploited Cisco, Citrix, and Fortinet edge-device flaws to KEV catalog, ordering federal agencies to patch by September 12, 2026.","summary":"CISA added CVE-2026-20079 (Cisco Secure Firewall Management Center authentication bypass, CVSS 10.0), CVE-2026-19490 (Citrix NetScaler ADC/Gateway authentication bypass, CVSS 9.3), and CVE-2025-25249 (FortiOS heap buffer overflow, CVSS 7.3) to the Known Exploited Vulnerabilities catalog with a September 12, 2026 deadline for FCEB agencies. Cisco confirmed active exploitation of CVE-2026-20079 in August 2026, while Previdian honeypots logged 56 NetScaler exploitation attempts since September 3. SOCRadar attributes Fortinet exploitation to a financially motivated Russian-speaking actor deploying the PivotC2 Node.js RAT, infecting 178 of over 3,000 targeted IP addresses, mostly in the US.","keyPoints":["CISA added three flaws to KEV with a September 12, 2026 federal patch deadline","Cisco FMC CVE-2026-20079 (CVSS 10.0) allows unauthenticated root access; exploited in August 2026","Citrix NetScaler bypass saw 56 honeypot exploitation attempts since September 3","Fortinet CVE-2025-25249 used to deploy PivotC2 Node.js RAT on 178 devices, mostly US","SOCRadar urges patching, IOC hunting, credential rotation, and limiting internet exposure"],"tags":["cisa","kev","cisco","citrix","netscaler","fortinet","fortios","pivotc2"],"entities":{"malware":["PivotC2"],"vendors":["CISA","Cisco","Citrix","Fortinet","Sygnia","SOCRadar","Previdian"],"victims":[],"products":["Cisco Secure Firewall Management Center","NetScaler ADC","NetScaler Gateway","FortiOS","FortiSwitchManager","FortiSASE","FortiGate"],"ai_models":[],"countries":["United States"],"organizations":[],"threat_actors":["Fire Ant"]},"cves":["CVE-2026-20079","CVE-2026-19490","CVE-2025-25249"],"inTheWild":true,"confidence":0.85,"clusterId":"91c160320310ca1b156d2c2449c074390263f265","extra":{"hint":null,"related":[{"url":"https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency","title":"Cybersecurity and Infrastructure Security Agency - Wikipedia","source":"en.wikipedia.org","snippet":"The Cybersecurity and Infrastructure Security Agency (CISA) is a component of the United States Department of Homeland Security (DHS) responsible for cybersecurity and information technology infrastructure protection. It oversees all levels of the federal government and coordinates with U.S. states to improve cybersecurity against private and nation-state hackers. [4] The CISA is headquartered ...","publishedAt":1789013700000},{"url":"https://niccs.cisa.gov/training/cisa-learning","title":"CISA Learning - NICCS","source":"niccs.cisa.gov","snippet":"CISA Learning, CISA’s Learning Management System (LMS), offers no-cost online cybersecurity training on topics such as cloud security, ethical hacking and surveillance, risk management, malware analysis, and more. CISA Learning replaced the Federal Virtual Training Environment (FedVTE) and multiple other LMS platforms.","publishedAt":1789008960000}],"related_at":1789040210443,"source_weight":1.2,"related_provider":"bing"},"sourceName":"The Hacker News","sourceHomepage":"https://thehackernews.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"d6c5f63fbe8fa46c672b65df48a4555f8057618b","sourceId":"securityweek","url":"https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/","title":"Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks","author":"Ionut Arghire","publishedAt":1789022016000,"fetchedAt":1789022923481,"feedSummary":"The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.\nThe post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek.","contentStatus":"ok","imageUrl":"https://www.securityweek.com/wp-content/uploads/2024/06/fortinet.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789022923481,"category":"exploit","severity":"high","importance":82,"tldr":"Threat actors exploit Fortinet heap-based buffer overflow CVE-2025-25249 to deploy PivotC2 RAT, infecting 178 devices and exfiltrating data from US targets.","summary":"SOCRadar reports exploitation of an unauthenticated remote code execution vulnerability, CVE-2025-25249 (CVSS 7.4), patched in January in FortiOS and FortiSwitchManager. Attackers scanned over 30,000 IP addresses, infected 178 devices with PivotC2 RAT, and at least two intrusions resulted in data exfiltration, primarily targeting US entities. SOCRadar attributes attacks to a likely Russian-speaking cybercrime actor and suggests the RAT was AI-assisted, in use since July 2026. CISA added the CVE to the KEV catalog with a three-day BOD 26-04 patch deadline for federal agencies.","keyPoints":["CVE-2025-25249 (CVSS 7.4) is a heap-based buffer overflow allowing unauthenticated RCE","178 devices infected with PivotC2 RAT after 30,000+ IP addresses targeted","Two US intrusions confirmed with data exfiltration","CISA added CVE to KEV with three-day federal patch deadline","Patch available in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6"],"tags":["fortinet","fortios","fortiswitchmanager","pivotc2","rat","cve-2025-25249","kev","socradar"],"entities":{"malware":["PivotC2"],"vendors":["Fortinet"],"victims":["US entities"],"products":["FortiOS","FortiSwitchManager","FortiGate"],"ai_models":[],"countries":["United States"],"organizations":["SOCRadar","CISA"],"threat_actors":["Russian-speaking cybercrime actor"]},"cves":["CVE-2025-25249"],"inTheWild":true,"confidence":0.92,"clusterId":"bdff752a92d12e85687c870587904c88e9714bef","extra":{"hint":null,"related":[],"related_at":1789022923481,"source_weight":1.1,"related_provider":"bing"},"sourceName":"SecurityWeek","sourceHomepage":"https://www.securityweek.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"bfdec184b6237b025371c3dd87e999b74b504dc7","sourceId":"canada-cccs","url":"https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-023","title":"Fortinet security advisory (AV26-023) - Update 1","author":"Canadian Centre for Cyber Security","publishedAt":1788983855000,"fetchedAt":1788985225519,"feedSummary":"Serial number: AV26-023\nDate: January 13, 2026\nUpdated: September 9, 2026\nOn January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:\nFortiFone 7.0 – versions 7.0.0 to 7.0.1\nFortiFone 3.0 – versions 3.0.13 to 3.0.23\nFortiOS 7.6 – versions 7.6.0 to 7.6.3\nFortiOS 7.4 – versions 7.4.0 to 7.4.8\nFortiOS 7.2 – versions 7.2.0 to 7.2.11\nFortiOS 7.0 – versions 7.0.0 to 7.0.17\nFortiOS 6.4 – versions 6.4.0 to 6.4.16\nFortiSASE 25.2 – version 25.2.b\nFortiSASE 25.1.a – version 25.1.a.2\nFortiSIEM 7.4 – version 7.4.0\nFortiSIEM 7.3 – versions 7.3.0 to 7.3.4\nFortiSIEM 7.2 – versions 7.2.0 to 7.2.6\nFortiSIEM 7.1…","contentStatus":"ok","imageUrl":"https://www.cyber.gc.ca/sites/default/files/images/cyber-open-graph.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788985225519,"category":"exploit","severity":"high","importance":60,"tldr":"CISA added Fortinet CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its KEV catalog; Canadian Cyber Centre urges patching.","summary":"The Canadian Centre for Cyber Security updated advisory AV26-023, which relays January 2026 Fortinet advisories covering FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager. On September 9, 2026, CISA added CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its Known Exploited Vulnerabilities catalog. Related Fortinet flaws include unauthenticated local configuration access (CVE-2025-47855) and unauthenticated remote command injection (CVE-2025-64155). Administrators should review the advisories and apply available updates.","keyPoints":["CVE-2025-25249 (heap overflow in cw_acd daemon) added to CISA KEV on September 9, 2026.","CVE-2025-47855 allows unauthenticated local configuration access; CVE-2025-64155 enables remote command injection.","Affected products span FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager."],"tags":["fortinet","fortios","fortifone","fortisiem","fortisase","cisa-kev","actively-exploited"],"entities":{"malware":[],"vendors":["Fortinet"],"victims":[],"products":["FortiOS","FortiFone","FortiSASE","FortiSIEM","FortiSwitchManager"],"ai_models":[],"countries":[],"organizations":["CISA","Canadian Centre for Cyber Security"],"threat_actors":[]},"cves":["CVE-2025-25249","CVE-2025-47855","CVE-2025-64155"],"inTheWild":true,"confidence":0.65,"clusterId":"bdff752a92d12e85687c870587904c88e9714bef","extra":{"hint":"advisory","source_weight":1},"sourceName":"Canadian Centre for Cyber Security","sourceHomepage":"https://www.cyber.gc.ca/en/alerts-advisories","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"595bf24c7d0b9916831b90ae385fe6855ca7c64e","sourceId":"securityweek","url":"https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/","title":"Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension","author":"Ionut Arghire","publishedAt":1788964432000,"fetchedAt":1788964675759,"feedSummary":"The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.\nThe post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.","contentStatus":"ok","imageUrl":"https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788964675759,"category":"vulnerability","severity":"high","importance":58,"tldr":"Fortinet patched 10 vulnerabilities including two critical authentication flaws, CVE-2026-84390 (CVSS 9.6) and CVE-2026-84388 (CVSS 9.1), in FortiMonitorOnSight and the FortiPAM Chrome extension.","summary":"Fortinet's September patch release fixes CVE-2026-84390, a sensitive-information issue in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs. CVE-2026-84388 is an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension that can allow attackers to proxy a user's browser traffic via a malicious website, requiring upgrades to both FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. High-severity information disclosure in FortiSandbox (CVE-2026-26084) and man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393) were also fixed, alongside medium/low issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others. Fortinet did not indicate any of the flaws are being exploited in the wild.","keyPoints":["CVE-2026-84390 (CVSS 9.6) enables JWT forgery to bypass FortiMonitorOnSight authentication","CVE-2026-84388 (CVSS 9.1) lets attackers proxy browser traffic through the FortiPAM Chrome extension","Fix requires coordinated upgrades of FortiPAM and extension 8.0.1.123+","High-severity fixes also cover FortiSandbox info disclosure and ZTNA portal MitM","No mention of in-the-wild exploitation"],"tags":["fortinet","fortipam","fortimonitoronsight","chrome-extension","jwt","auth-bypass","ztna","patch"],"entities":{"malware":[],"vendors":["Fortinet"],"victims":[],"products":["FortiMonitorOnSight","FortiPAM","FortiSandbox","FortiOS","FortiProxy","FortiManager","FortiAnalyzer","FortiSOAR","FortiClient","FortiSIEM"],"ai_models":[],"countries":[],"organizations":["Fortinet"],"threat_actors":[]},"cves":["CVE-2026-84390","CVE-2026-84388","CVE-2026-26084","CVE-2026-84393"],"inTheWild":false,"confidence":0.95,"clusterId":"09823557f1c3cf7ed4cdf391ae4f5e29b587e1c6","extra":{"hint":null,"source_weight":1.1},"sourceName":"SecurityWeek","sourceHomepage":"https://www.securityweek.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"a6f32e10291c2e9c1d49d8446d5ee815e6749929","sourceId":"canada-cccs","url":"https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-898","title":"Fortinet security advisory (AV26-898)","author":"Canadian Centre for Cyber Security","publishedAt":1788961726000,"fetchedAt":1788962275643,"feedSummary":"Serial Number: AV26-898\nDate: September 9, 2026\nAs of September 8, 2026, Fortinet is affected by vulnerabilities in the following products:\nFortiOS 7.6\nVersions 7.6.1 to 7.6.6\nFortiProxy 7.6\nVersions 7.6.2 to 7.6.6\nFortiPAM Chrome Extension 8.0\nAll versions\nFortiPAM Chrome Extension 7.4\nAll versions\nFortiSandbox 5.0\nVersions 5.0.0 to 5.0.5\nFortiSandbox 4.4\nVersions 4.4.0 to 4.4.8\nFortiSandbox Cloud 5.0\nVersions 5.0.4 to 5.0.5\nFortiSandbox PaaS 5.0\nVersions 5.0.4 to 5.0.5\nFortiMonitorOnSight 7.2\nVersions 7.2.4 to 7.2.7\nFortiMonitorOnSight 7.2\nVersions 7.2.0 to 7.2.2\nThe Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\nFortinet…","contentStatus":"ok","imageUrl":"https://www.cyber.gc.ca/sites/default/files/images/cyber-open-graph.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788962275643,"category":"advisory","severity":"medium","importance":26,"tldr":"Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates","summary":"The Canadian Centre for Cyber Security relayed Fortinet PSIRT advisories (AV26-898) listing vulnerabilities affecting FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2. The bulletin does not detail individual CVEs or exploitation. Administrators and users are encouraged to review the linked Fortinet advisories and apply the necessary updates.","keyPoints":["Covers FortiOS 7.6, FortiProxy 7.6, FortiPAM extensions, FortiSandbox 4.4/5.0, FortiMonitorOnSight 7.2","Advisory AV26-898 urges review of linked Fortinet PSIRT advisories and prompt patching","No specific CVE identifiers or exploitation details provided in the bulletin"],"tags":["fortinet","fortios","fortiproxy","fortipam","fortisandbox","advisory","canada"],"entities":{"malware":[],"vendors":["Fortinet"],"victims":[],"products":["FortiOS","FortiProxy","FortiPAM","FortiSandbox","FortiMonitorOnSight"],"ai_models":[],"countries":["Canada"],"organizations":["Canadian Centre for Cyber Security"],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.9,"clusterId":"b5c62413db914cf92d648c4229400f5dbb6fbbc2","extra":{"hint":"advisory","source_weight":1},"sourceName":"Canadian Centre for Cyber Security","sourceHomepage":"https://www.cyber.gc.ca/en/alerts-advisories","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"09823557f1c3cf7ed4cdf391ae4f5e29b587e1c6","sourceId":"gbhackers","url":"https://gbhackers.com/fortipam-chrome-extension-vulnerability/","title":"FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs","author":"Divya","publishedAt":1788959930000,"fetchedAt":1788961075542,"feedSummary":"A critical vulnerability has been identified in the Fortinet FortiPAM Chrome extension that could allow a malicious website to manipulate browser proxy settings, open tabs at the attacker’s discretion, and record activity within those tabs. This issue, tracked as CVE-2026-84388 and rated with a CVSS score of 9.1, impacts an extension that facilitates privileged access […]\nThe post FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.","contentStatus":"ok","imageUrl":"https://gbhackers.com/wp-content/uploads/2026/09/8616461a-53ae-445f-b758-8836c08c789e-2.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788961075542,"category":"vulnerability","severity":"high","importance":48,"tldr":"Fortinet patched CVE-2026-84388 (CVSS 9.1) in its FortiPAM Chrome extension, letting malicious websites alter proxy settings, open tabs and record sessions.","summary":"The Fortinet FortiPAM Chrome extension flaw (CVE-2026-84388, CVSS 9.1) lets attacker-controlled domains be trusted as FortiPAM servers because a webRequest listener adds requested hostnames without verifying the initiator. A second issue exposes the extension's message interface to all URLs and accepts non-JWT tokens without validation, enabling unauthenticated session launches, proxy manipulation, tab control and recording; the consent dialog can also be bypassed via shadow-root clicks. Fortinet issued advisory FG-IR-26-168 after a July 17 report and released a fix on August 1, 2026, with no confirmed exploitation in the wild.","keyPoints":["webRequest listener trusts hostnames without validating initiator, letting attacker domains pose as FortiPAM servers","externally_connectable all_urls plus token validation gaps allow unauthenticated session launches and proxy control","Consent dialog rendered in page DOM can be auto-accepted via shadow-root clicks","Fix released August 1 in advisory FG-IR-26-168; no in-the-wild exploitation confirmed"],"tags":["fortinet","fortipam","chrome-extension","browser-security","cve","patch"],"entities":{"malware":[],"vendors":["Fortinet"],"victims":[],"products":["FortiPAM"],"ai_models":[],"countries":[],"organizations":["Am I Being Pwned"],"threat_actors":[]},"cves":["CVE-2026-84388"],"inTheWild":false,"confidence":0.88,"clusterId":"09823557f1c3cf7ed4cdf391ae4f5e29b587e1c6","extra":{"hint":null,"source_weight":0.7},"sourceName":"GBHackers","sourceHomepage":"https://gbhackers.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"8a7092d1bea5da0f72a24f97b9fae8fe30348514","sourceId":"gbhackers","url":"https://gbhackers.com/fake-linkedin-job-offers/","title":"Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs","author":"Mayura Kathir","publishedAt":1788958340000,"fetchedAt":1788958675348,"feedSummary":"Iran-linked cyberespionage group Mirage Kitten is targeting software engineers with fake recruiter outreach on LinkedIn and job-search platforms. Using trojanized coding assessments to deploy two previously undocumented cross-platform remote access trojans: NodeRabbit and PollCat. The campaign targets developer workstations across Windows, Linux, and macOS, with victims identified in aviation, aerospace, and fintech organizations in Egypt, […]\nThe post Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.","contentStatus":"ok","imageUrl":"https://gbhackers.com/wp-content/uploads/2026/09/1f371ef6-9d4f-404b-9298-12a95cbf5c3b.png","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788958675348,"category":"threat-actor","severity":"high","importance":72,"tldr":"Iran-linked Mirage Kitten targets software engineers with fake LinkedIn recruiter coding tests deploying new NodeRabbit and PollCat RATs.","summary":"Kaspersky researchers link the campaign to Mirage Kitten (also tracked as UNC1549, Smoke Sandstorm, Nimbus Manticore), with victims in aviation, aerospace and fintech in Egypt, Ethiopia and Afghanistan. Trojanized npm dependencies (colorized_terminal, pretty-log) bundled in coding-challenge archives launch the Node.js implants across Windows, Linux and macOS. NodeRabbit uses AES-256-GCM-encrypted C2 via Azure, and its third variant persists through a fake GitHub Copilot Helper VS Code extension plus Git post-merge/post-checkout hooks. PollCat is an obfuscated JavaScript RAT that registers with C2 before OTP authentication and inventories tools from 24 security vendors.","keyPoints":["Fake recruiter personas deliver Front-Technical-Challenge.zip and RankChallenge-react tests with three-hour deadlines.","Malicious packages ship inside bundled node_modules, not the npm registry, evading registry trust.","NodeRabbit variant masquerades as GitHub Copilot Helper extension and abuses Git hooks for persistence.","PollCat checks for 24 security vendors including CrowdStrike, SentinelOne, Fortinet and Microsoft.","First documented shift from Mirage Kitten's native C, C++ and Go tooling to Node.js."],"tags":["mirage-kitten","unc1549","noderabbit","pollcat","kaspersky","iran","nodejs","supply-chain"],"entities":{"malware":["NodeRabbit","PollCat"],"vendors":["Kaspersky","Microsoft","CrowdStrike","Fortinet"],"victims":[],"products":["NodeRabbit","PollCat","Visual Studio Code","GitHub Copilot"],"ai_models":[],"countries":["Egypt","Ethiopia","Afghanistan","Iran"],"organizations":["Kaspersky","Microsoft","Google","Cloudflare"],"threat_actors":["Mirage Kitten","UNC1549","Smoke Sandstorm","Nimbus Manticore"]},"cves":[],"inTheWild":true,"confidence":0.85,"clusterId":"8a7092d1bea5da0f72a24f97b9fae8fe30348514","extra":{"hint":null,"source_weight":0.7},"sourceName":"GBHackers","sourceHomepage":"https://gbhackers.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"1785554c5d6d6a99ebce9412f8c6a0240d37b328","sourceId":"cisa-advisories","url":"https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog","title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog","author":"CISA","publishedAt":1788955200000,"fetchedAt":1788985225519,"feedSummary":"CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.\nCVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability\nCVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability\nCVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability\nCVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability\nThese types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.\nBinding Operational Directive (BOD) 26-04:…","contentStatus":"ok","imageUrl":null,"domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788985225519,"category":"exploit","severity":"high","importance":75,"tldr":"CISA added four actively exploited vulnerabilities—Fortinet buffer overflow, Citrix NetScaler and Cisco auth bypasses, and a Chromium V8 write—to the KEV Catalog.","summary":"CISA added CVE-2025-25249 (Fortinet heap-based buffer overflow), CVE-2026-19490 (Citrix NetScaler authentication bypass), CVE-2026-87491 (Google Chromium V8 out-of-bounds write), and CVE-2026-20079 (Cisco Firewall Management Center authentication bypass) to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of these high-risk vulnerabilities on exposed assets and verify whether systems were compromised before patching. CISA encourages all organizations to adopt risk-based vulnerability management and prioritize KEV Catalog remediation.","keyPoints":["Four vulnerabilities added to KEV based on evidence of active exploitation.","Affected vendors: Fortinet, Citrix NetScaler, Google Chromium V8, Cisco Firewall Management Center.","BOD 26-04 requires FCEB agencies to rapidly patch high-risk KEV vulnerabilities on exposed assets.","Agencies must also check whether threat actors compromised systems before patching.","CISA urges all organizations to prioritize KEV remediation and nominate exploited flaws via its form."],"tags":["cisa","kev","fortinet","citrix","netscaler","cisco","chromium","v8"],"entities":{"malware":[],"vendors":["Fortinet","Citrix","Google","Cisco"],"victims":[],"products":["Fortinet Firewall","Citrix NetScaler","Google Chromium","Cisco Firewall Management Center"],"ai_models":[],"countries":[],"organizations":["CISA"],"threat_actors":[]},"cves":["CVE-2025-25249","CVE-2026-19490","CVE-2026-87491","CVE-2026-20079"],"inTheWild":true,"confidence":0.85,"clusterId":"1785554c5d6d6a99ebce9412f8c6a0240d37b328","extra":{"hint":"advisory","related":[],"related_at":1788985225519,"source_weight":1.5,"related_provider":"bing"},"sourceName":"CISA Advisories","sourceHomepage":"https://www.cisa.gov/news-events/cybersecurity-advisories","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"bdff752a92d12e85687c870587904c88e9714bef","sourceId":"gbhackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/","title":"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT","author":"Divya","publishedAt":1788944271000,"fetchedAt":1788945474356,"feedSummary":"Threat actors are actively exploiting a critical vulnerability in FortiGate to deploy PivotC2, a Node. js-based remote access trojan (RAT) designed for persistent post-exploitation of FortiOS appliances. Researchers at SOCRadar’s Threat Research Unit (STRU) reported that this campaign has targeted over 30,000 internet-exposed FortiGate IP addresses and has successfully compromised at least 178 devices since […]\nThe post Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.","contentStatus":"ok","imageUrl":"https://gbhackers.com/wp-content/uploads/2026/09/656a683b-ea4a-4fc7-8b2a-b03a4eab8914-1.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788945474356,"category":"malware","severity":"high","importance":72,"tldr":"SOCRadar says attackers exploit FortiGate CVE-2025-25249 to deploy the PivotC2 Node.js RAT, compromising 178 of 30,000 targeted devices and stealing credentials.","summary":"SOCRadar's Threat Research Unit reports active exploitation of CVE-2025-25249, a CVSS 9.8 heap-based buffer overflow in the cw_acd daemon of FortiOS and FortiSwitchManager, via crafted CAPWAP requests to UDP port 5246, compromising at least 178 of 30,000 targeted internet-exposed FortiGate devices since July 2026. The campaign deploys PivotC2, a Node.js RAT that provides interactive shells, SOCKS5/HTTP proxying, port forwarding, network scanning, and automated configuration harvesting that decrypts stored FortiGate credentials, including VPN pre-shared keys, SSL-VPN credentials, and LDAP secrets. Russian-language artifacts, AD enumeration, browser credential theft, RDP enablement, and exfiltration of Exchange .pst files to Wasabi S3 point to a Russian-speaking, financially motivated group; two US organizations confirmed full-network intrusions. Fixes include FortiOS 7.6.4/7.4.9/7.2.12/7.0.18+ and FortiSwitchManager 7.2.7/7.0.6+, plus blocking CAPWAP on internet-facing interfaces.","keyPoints":["178 of 30,000 exposed FortiGate devices compromised since July 2026","PivotC2 decrypts fsv_sync.dat exposing VPN, SSL-VPN, LDAP secrets","US most affected, then Chile, Colombia, UK; two US orgs breached","Block UDP 5246-5249; hunt for /tmp/.i.js and Node.js processes","Rotate appliance, VPN, LDAP, wireless, and IPSec credentials"],"tags":["fortigate","fortios","pivotc2","rat","nodejs","capwap","socradar","credential-theft"],"entities":{"malware":["PivotC2"],"vendors":["Fortinet"],"victims":[],"products":["FortiGate","FortiOS","FortiSwitchManager"],"ai_models":[],"countries":["United States","Chile","Colombia","United Kingdom"],"organizations":["SOCRadar","Wasabi"],"threat_actors":[]},"cves":["CVE-2025-25249"],"inTheWild":true,"confidence":0.68,"clusterId":"bdff752a92d12e85687c870587904c88e9714bef","extra":{"hint":null,"source_weight":0.7},"sourceName":"GBHackers","sourceHomepage":"https://gbhackers.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"e0c581653532e70a1def43f92fea2339615a9698","sourceId":"gbhackers","url":"https://gbhackers.com/best-managed-xdr-compared/","title":"The 12 Best Managed XDR Services, Compared and Priced","author":"Kavichselvan","publishedAt":1788941236000,"fetchedAt":1788942136567,"feedSummary":"Best value overall: Bitdefender — competent managed XDR at pricing that mid-market organizations can approve, which most of this list cannot claim. Best detection research: Secureworks Taegis. Best telemetry breadth: Palo Alto Unit 42. Best for keeping your existing tools: Stellar Cyber and ReliaQuest. Best Microsoft-native: Ontinue. MXDR is MDR with a wider aperture and […]\nThe post The 12 Best Managed XDR Services, Compared and Priced appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.","contentStatus":"ok","imageUrl":"https://gbhackers.com/wp-content/uploads/2026/08/Best-Managed-XDR-Services.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788942136567,"category":"industry","severity":"info","importance":15,"tldr":"A comparison of twelve managed XDR providers covering pricing models, telemetry breadth, and distinguishing genuine MXDR from rebranded MDR services.","summary":"The article compares twelve managed XDR providers including Bitdefender, CrowdStrike, Palo Alto Unit 42, Trend Micro, Fortinet, Secureworks Taegis, Stellar Cyber, Ontinue, and ReliaQuest, highlighting pricing models and telemetry breadth. It explains that genuine MXDR must actively monitor identity, cloud, and email telemetry rather than merely ingest it, and typically costs 30-60% more than endpoint-only MDR. It also notes Sophos completed its approximately $859 million acquisition of Secureworks in February 2025.","keyPoints":["Genuine MXDR ingests and actively monitors identity, cloud, and email telemetry","MXDR typically costs 30-60% more than endpoint-only MDR","Sophos acquired Secureworks for approximately $859 million in February 2025"],"tags":["mdr","xdr","vendor-comparison","pricing","managed-services"],"entities":{"malware":[],"vendors":["Bitdefender","CrowdStrike","Palo Alto Networks","Trend Micro","Fortinet","Secureworks","Sophos","Huntress"],"victims":[],"products":["Cortex XDR","Falcon","Taegis"],"ai_models":[],"countries":[],"organizations":["Sophos"],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.9,"clusterId":"39e2b98ad279939239bf42b0ca76c8a18baabca3","extra":{"hint":null,"source_weight":0.7},"sourceName":"GBHackers","sourceHomepage":"https://gbhackers.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"4c059e0962b84d64fabfb595a9fd8dfe433717b1","sourceId":"gbhackers","url":"https://gbhackers.com/fortinet-fortisandbox-vulnerability-3/","title":"Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information","author":"Divya","publishedAt":1788938140000,"fetchedAt":1788938536271,"feedSummary":"Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an unauthenticated remote attacker to access sensitive information by sending specially crafted HTTP requests. The vulnerability is tracked as CVE-2026-26084 and documented in advisory FG-IR-26-166. It affects the graphical user interface (GUI) component of FortiSandbox, FortiSandbox […]\nThe post Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.","contentStatus":"ok","imageUrl":"https://gbhackers.com/wp-content/uploads/2026/09/72234d48-7ade-4673-8108-e7b7c62b8845-1.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788938536271,"category":"vulnerability","severity":"high","importance":58,"tldr":"Fortinet fixed CVE-2026-26084, an unauthenticated access-control flaw in FortiSandbox GUI rated 8.9 CVSS, with no known exploitation yet.","summary":"Fortinet disclosed CVE-2026-26084 (advisory FG-IR-26-166), a CWE-284 improper access control flaw in the GUI of FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS, rated 8.9 CVSS v3.1. An unauthenticated remote attacker can send specially crafted HTTP requests to control NAT rules and expose sensitive information. Affected versions include FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5 (plus Cloud/PaaS 5.0.4-5.0.5), fixed in 4.4.9 and 5.0.6. Fortinet researcher Adham El Karn found the flaw internally and the September 8 advisory reports no known exploitation.","keyPoints":["Unauthenticated HTTP requests to the GUI can expose sensitive data via NAT rule control.","Fixed versions are 4.4.9+ and 5.0.6+; 5.2 lines are unaffected.","Fortinet assigned CVSS 8.9; no public PoC or exploitation reported.","Defenders should restrict GUI access to management networks and review logs for anomalous requests."],"tags":["fortinet","fortisandbox","access-control","information-disclosure","cve-2026-26084","patching"],"entities":{"malware":[],"vendors":["Fortinet"],"victims":[],"products":["FortiSandbox"],"ai_models":[],"countries":[],"organizations":["Fortinet PSIRT"],"threat_actors":[]},"cves":["CVE-2026-26084"],"inTheWild":false,"confidence":0.95,"clusterId":"65d72e658313e16a85cb45d24499adb22f90c2ca","extra":{"hint":null,"source_weight":0.7},"sourceName":"GBHackers","sourceHomepage":"https://gbhackers.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"b5c62413db914cf92d648c4229400f5dbb6fbbc2","sourceId":"zdi-advisories","url":"http://www.zerodayinitiative.com/advisories/ZDI-26-645/","title":"ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability","author":null,"publishedAt":1788930000000,"fetchedAt":1788994175142,"feedSummary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.","contentStatus":"skipped","imageUrl":null,"domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788994175142,"category":"advisory","severity":"medium","importance":26,"tldr":"ZDI publishes ZDI-26-645 for CVE-2026-84387, an authenticated command injection RCE in Fortinet FortiSandbox via crontab backup, rated CVSS 7.2.","summary":"Zero Day Initiative published advisory ZDI-26-645 describing a command injection flaw in Fortinet FortiSandbox's write_remote_backup_to_crontab function. Remote authenticated attackers can execute arbitrary code through the cronValue parameter. ZDI rated the issue CVSS 7.2 and assigned CVE-2026-84387.","keyPoints":["Command injection via cronValue in the crontab backup function","Authentication is required to exploit the flaw","CVSS 7.2; tracked as CVE-2026-84387"],"tags":["fortinet","fortisandbox","rce","command-injection","zdi","advisory"],"entities":{"malware":[],"vendors":["Fortinet"],"victims":[],"products":["FortiSandbox"],"ai_models":[],"countries":[],"organizations":["Zero Day Initiative"],"threat_actors":[]},"cves":["CVE-2026-84387"],"inTheWild":false,"confidence":0.72,"clusterId":"b5c62413db914cf92d648c4229400f5dbb6fbbc2","extra":{"hint":"advisory","source_weight":0.9},"sourceName":"ZDI Published Advisories","sourceHomepage":"https://www.zerodayinitiative.com/advisories/published/","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"65d72e658313e16a85cb45d24499adb22f90c2ca","sourceId":"cybersecuritynews","url":"https://cybersecuritynews.com/fortisandbox-vulnerability-access-sensitive-data/","title":"FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests","author":"Guru Baran","publishedAt":1788923306000,"fetchedAt":1788924135347,"feedSummary":"Fortinet has disclosed a new high-severity vulnerability affecting its FortiSandbox platform, warning that unauthenticated attackers could exploit weaknesses in the product’s web interface to siphon off sensitive information without ever needing valid credentials. The flaw, tracked as CVE-2026-26084, stems from improper access control in the graphical user interface component that FortiSandbox, FortiSandbox Cloud, and FortiSandbox […]\nThe post FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests appeared first on Cyber Security News.","contentStatus":"ok","imageUrl":"https://cybersecuritynews.com/wp-content/uploads/2026/09/FortiSandbox-Vulnerability-access-sensitive-Data.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788924135347,"category":"vulnerability","severity":"high","importance":48,"tldr":"Fortinet disclosed CVE-2026-26084 (CVSS 8.9), an unauthenticated information-disclosure flaw in the FortiSandbox web UI, urging upgrades.","summary":"Fortinet patched CVE-2026-26084, a CWE-284 improper access control flaw in the shared web UI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that lets unauthenticated attackers read sensitive data via crafted HTTP requests. Affected releases include FortiSandbox 5.0.0-5.0.5 and 4.4.0-4.4.8, Cloud 5.0.4-5.0.5, and PaaS 5.0.4-5.0.5; fixes arrive in 5.0.6+ and 4.4.9+, while FortiSandbox 5.2 and Cloud 4.4 are unaffected. The issue was found internally by Fortinet's Product Security team, and the company reports no evidence of exploitation in the wild. Disclosure carries only confidentiality impact, but exposed sandbox configurations and logs could aid follow-on attacks.","keyPoints":["CVE-2026-26084 rated CVSS 8.9, unauthenticated info disclosure via crafted HTTP requests","Impacts FortiSandbox on-premises, Cloud, and PaaS web UI components","Fix in 5.0.6+ or 4.4.9+; 5.2 and Cloud 4.4 unaffected","No user interaction or privileges needed; no code execution","Fortinet says no evidence of in-the-wild exploitation"],"tags":["fortinet","fortisandbox","cve-2026-26084","access-control","information-disclosure","web-ui","patching"],"entities":{"malware":[],"vendors":["Fortinet"],"victims":[],"products":["FortiSandbox"],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2026-26084"],"inTheWild":false,"confidence":0.95,"clusterId":"65d72e658313e16a85cb45d24499adb22f90c2ca","extra":{"hint":null,"source_weight":0.7},"sourceName":"Cyber Security News","sourceHomepage":"https://cybersecuritynews.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"b5b7b9c19bfea59deb7c3a592c194133752300d4","sourceId":"gbhackers","url":"https://gbhackers.com/best-managed-firewall-services-compared/","title":"The 12 Best Managed Firewall Services, Compared and Priced","author":"Kavichselvan","publishedAt":1788862803000,"fetchedAt":1788880415389,"feedSummary":"Best value overall: Fortinet. Delivered directly and through the largest partner network in security, at price points the premium providers can’t approach provided you vet the actual delivery partner. Best detection quality: Secureworks. Best global reach: NTT Data. Best if you want to stop owning firewalls: Cato Networks. Best for SMB: Barracuda MSP. Managed firewall […]\nThe post The 12 Best Managed Firewall Services, Compared and Priced appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.","contentStatus":"ok","imageUrl":"https://gbhackers.com/wp-content/uploads/2026/08/Best-Managed-Firewall-Services-1.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788880415389,"category":"industry","severity":"info","importance":12,"tldr":"GBHackers compares 12 managed firewall service providers, naming Fortinet best value and Secureworks best detection while flagging recent ownership changes.","summary":"The buyer's guide evaluates 12 managed firewall/MSSP providers across cost tiers, contract terms, and service models. Fortinet is rated best value, Secureworks best detection, NTT Data best global reach, and Cato Networks best for organizations wanting to stop owning firewalls. The article highlights that Secureworks was acquired by Sophos for roughly $859 million in February 2025, the Trustwave-Cybereason merger was terminated in March 2025, LevelBlue is the rebranded AT&T Cybersecurity business, and Comcast Business absorbed Masergy.","keyPoints":["Fortinet rated best value; Secureworks best detection; NTT Data best global reach.","Sophos completed the ~$859M Secureworks acquisition in February 2025.","Trustwave-Cybereason merger was announced then terminated on 10 March 2025.","LevelBlue is rebranded AT&T Cybersecurity; Comcast Business absorbed Masergy."],"tags":["managed-firewall","mssp","buyers-guide","fortinet","secureworks","sophos","cato-networks"],"entities":{"malware":[],"vendors":["Fortinet","Secureworks","Sophos","NTT Data","Cato Networks","Barracuda","Trustwave","Cybereason","LevelBlue","AT&T"],"victims":[],"products":["FortiGate","Taegis"],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.85,"clusterId":"b5b7b9c19bfea59deb7c3a592c194133752300d4","extra":{"hint":null,"source_weight":0.7},"sourceName":"GBHackers","sourceHomepage":"https://gbhackers.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"26eab577d4d31262ad6573ab79a8cf47b79140ed","sourceId":"socradar","url":"https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/","title":"CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT","author":"ameer","publishedAt":1788861627000,"fetchedAt":1788945474356,"feedSummary":"CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT One of the most common entry points for attackers is the exploitation of public-facing edge devices (such as VPNs, routers, and firewalls).","contentStatus":"failed","imageUrl":"https://socradar.io/wp-content/uploads/2026/09/socradar-vulnerability-intelligence-vendor-filtering-fortinet.jpg.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788945474356,"category":"exploit","severity":"high","importance":74,"tldr":"Attackers exploiting CVE-2025-25249 in Fortinet FortiGate firewalls deploy PivotC2, a post-exploitation RAT, on exposed edge devices.","summary":"SOCRadar reports that exploitation of CVE-2025-25249 is being used to deploy PivotC2, a purpose-built post-exploitation RAT, on FortiGate firewall appliances. The attack follows the common pattern of compromising public-facing edge devices such as VPNs, routers, and firewalls as the initial entry point. Defenders running FortiGate appliances should prioritize patching and watch for post-exploitation activity indicating RAT deployment.","keyPoints":["CVE-2025-25249 exploitation on FortiGate delivers the PivotC2 post-exploitation RAT","Public-facing edge devices like VPNs, routers, and firewalls are common initial entry points","FortiGate operators should patch and monitor for post-exploitation indicators"],"tags":["fortinet","fortigate","cve-2025-25249","pivotc2","rat","edge-devices","post-exploitation"],"entities":{"malware":["PivotC2"],"vendors":["Fortinet","SOCRadar"],"victims":[],"products":["FortiGate"],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2025-25249"],"inTheWild":true,"confidence":0.86,"clusterId":"26eab577d4d31262ad6573ab79a8cf47b79140ed","extra":{"hint":null,"source_weight":0.7},"sourceName":"SOCRadar","sourceHomepage":"https://socradar.io/blog/","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"5b95c968d0d2ff5f6ef1fc5bf14a1796325725a8","sourceId":"cyble","url":"https://cyble.com/blog/qatar-digital-boom-blindspot/","title":"Qatar’s Digital Boom Has a Blind Spot: What the 2025-26 Threat Data Is Telling Us","author":"Mihir Bagwe","publishedAt":1788786048000,"fetchedAt":1788880415389,"feedSummary":"Qatar is racing toward a knowledge-based, fully digital economy. Smart infrastructure, cloud-first government services, a financial sector that's increasingly API-driven, and critical energy assets like QatarEnergy's LNG operations layering more connected OT/ICS systems every year. That pace of transformation makes Qatar an attractive target in the cyber realm, right now. Attackers don't need to compromise everything; they just need one high-value foothold, and Qatar's expanding digital footprint keeps handing them more doors to try.\nThis risk is showing up in the data as well.\nThe Problem: A Small, Concentrated, High-Precision Threat\nUnlike sprawling, high-volume threat landscapes…","contentStatus":"ok","imageUrl":"https://cyble.com/wp-content/uploads/2026/09/blog-banner-qatar-cysec-2026-cyble.png","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788880415389,"category":"threat-actor","severity":"medium","importance":40,"tldr":"Cyble's Qatar Threat Landscape Report 2025-26 finds Qilin dominated local ransomware while access brokers concentrated on Qatari BFSI and retail access sales.","summary":"Cyble's Qatar Threat Landscape Report 2025-26 describes a concentrated threat environment where Qilin accounted for essentially all observed ransomware activity in the country in 2025, including an October campaign, with The Gentleman, Everest, Crypto24, and Payload sharing the space in 2026. Access brokers are selling compromised access, with BFSI and retail accounting for more than half of underground listings, while the education sector sees the most breach and leak incidents. Exploitation activity surged for enterprise remote-access products from Microsoft, Fortinet, Ivanti, and Citrix. The report was published ahead of the CYSEC Qatar summit and cites Qatar's data privacy law and National Cyber Security Agency initiatives.","keyPoints":["Qilin was responsible for essentially all ransomware activity observed in Qatar in 2025","Access broker listings tied to Qatar concentrate on BFSI and retail, over half of listings","Education sector records the most data leaks, often via opportunistic PII harvesting","Exploitation spiked in remote-access tools from Microsoft, Fortinet, Ivanti, and Citrix","Hacktivism is low-volume and narrative-driven amid regional geopolitical tensions"],"tags":["qatar","qilin","ransomware","access-brokers","threat-landscape","hacktivism","ot-ics"],"entities":{"malware":[],"vendors":["Cyble","Microsoft","Fortinet","Ivanti","Citrix"],"victims":["QatarEnergy"],"products":["N-central"],"ai_models":[],"countries":["Qatar"],"organizations":[],"threat_actors":["Qilin","The Gentleman","Everest","Crypto24","Payload"]},"cves":[],"inTheWild":true,"confidence":0.8,"clusterId":"5b95c968d0d2ff5f6ef1fc5bf14a1796325725a8","extra":{"hint":null,"source_weight":0.8},"sourceName":"Cyble","sourceHomepage":"https://cyble.com/blog/","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"78a351450324c00bcf66e73df7257256e9debc30","sourceId":"thehackernews","url":"https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html","title":"BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory","author":"info@thehackernews.com (The Hacker News)","publishedAt":1788449207000,"fetchedAt":1788876201158,"feedSummary":"Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.\n\"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial","contentStatus":"ok","imageUrl":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9vYkFCrVzaEl0WQj4XBILj6pIxDJ92eWgVrkOa_pdvJJoKF95JCX7VmQzY0HPZkhg5IMvjfCu15YCs5AMJ22NM6SBX7j7sCgpfiaUZZAL4Uc5vP0-q9VKN4LNSY4a701mmRCgLJQxCjnmnsSAxD7gFnyf9-dRaSxPZuGqLuOIQ415vCOjH-DZRtYSBHA/s1600/access-for-sale.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788881640544,"category":"malware","severity":"medium","importance":45,"tldr":"Group-IB details BraZetsu, a modular Python Windows malware that monetizes compromised-host access through the Infected Marketplace for initial access brokers.","summary":"Group-IB attributes BraZetsu to the Exilware threat actor, believed to be native Portuguese speakers targeting Iberian and Latin American e-commerce, financial, industrial, and law enforcement victims. The framework, first observed in early May 2026, uses generative AI for data triage and target prioritization, steals browser histories and digital certificates, and hunts Brazilian CNAB financial remittance files. Access to compromised hosts is sold on the Infected Marketplace from roughly $5.80, letting buyers remotely deploy secondary payloads over WebSocket-linked infrastructure. Some samples evaded detection on VirusTotal; delivery likely uses VBS loaders from a domain also used to distribute the Ousaban banking trojan.","keyPoints":["Modular Python toolkit supports reconnaissance, remote shell execution, and worker module deployment","Uses generative AI for backend data triage and high-value target prioritization","Targets CNAB financial remittance files used for Brazil bank-corporate transactions","Overlaps with CNABHunter, which rewrites CNAB payment files with attacker-controlled PIX keys","Access sold on Infected Marketplace with an initial deposit around $5.80"],"tags":["brazetsu","exilware","group-ib","python-malware","infostealer","initial-access-broker","cnab","latin-america"],"entities":{"malware":["BraZetsu","CNABHunter","Ousaban"],"vendors":["Group-IB","Fortinet"],"victims":[],"products":["BraZetsu","CNABHunter"],"ai_models":[],"countries":["Brazil","Spain","Portugal"],"organizations":[],"threat_actors":["Exilware"]},"cves":[],"inTheWild":true,"confidence":0.85,"clusterId":"78a351450324c00bcf66e73df7257256e9debc30","extra":{"hint":null,"source_weight":1.2},"sourceName":"The Hacker News","sourceHomepage":"https://thehackernews.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"a96b7528b8382c4c5bdd562b551f02f49acc08d8","sourceId":"thehackernews","url":"https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html","title":"FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations","author":"@TheHackersNews","publishedAt":1788330406000,"fetchedAt":1789019629125,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRjXW8RS8eKAVsCBovWfkRO7QMTfrgvWcTQtLccJCxq6wXC4OhegU26JXGqEKA0zS951ogEjKmNugfT1jDKlC8Kff6m-LZm-AFQe8Y57c1H_d44_bJPayRw-HpXwbb_MmN3pds3BdBUziNNBlAA_nHqX-BTb6nQLQWrKgJYnpqikUzENaV68VpD9LHsQlX/s1700-nu-rw-lo-l85-e365/chinese.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789022923481,"category":"threat-actor","severity":"high","importance":78,"tldr":"FBI and Lumen disrupted QTFY's QScan and QTRouter botnet platforms used by Chinese state-sponsored hackers to conceal intrusions into U.S. agencies.","summary":"The U.S. DoJ announced court-authorized seizure of domains behind QScan and QTRouter, operated by the Chinese state-sponsored group QTFY and employed by Nanjing Xinjiuwei Network Technology Company. QTFY has been active since May 2018 and targeted NASA, the Federal Reserve, the Department of Energy, DoJ, HHS, NIH, the U.S. Senate, and academic institutions. QScan exploits vulnerable IoT devices, feeding them into QTRouter, an OpenWrt-based proxy obfuscation network likened to an operational relay box (ORB) that masks attack origins. The group exploited zero-days such as Ivanti CSA flaws CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380, plus numerous N-days, and maintained persistence with RATs, web shells, and legitimate credentials.","keyPoints":["QScan exploits vulnerable IoT devices worldwide; QTRouter is an OpenWrt/Clash proxy network hiding Chinese attack origins.","Targets included NASA, the Federal Reserve, DoE, DoJ, HHS, NIH, and the U.S. Senate.","Infrastructure resembles an ORB, mixing compromised IoT devices with commercial proxy services and leased VPSes.","Initial access leveraged Ivanti CSA zero-days and N-days in Exchange, Log4j, Confluence, F5, and others.","Seized hard-coded domains caused both platforms to cease operations after the takedown."],"tags":["qtfy","qscan","qtrouter","china","state-sponsored","botnet","orb","iot"],"entities":{"malware":["QTBotnet"],"vendors":["Fortinet","Citrix","Microsoft","F5","Kentico","Apache","Atlassian","Check Point","CrushFTP","BeyondTrust"],"victims":["NASA","Federal Reserve","Department of Energy","Department of Justice","Department of Health and Human Services","NIH","U.S. Senate"],"products":["QScan","QTRouter","Ivanti CSA","OpenWrt","Clash"],"ai_models":[],"countries":["China","United States"],"organizations":["FBI","Department of Justice","Lumen Black Lotus Labs","Nanjing Xinjiuwei Network Technology Company","Ministry of State Security","People's Liberation Army"],"threat_actors":["QTFY"]},"cves":["CVE-2018-13379","CVE-2019-10068","CVE-2019-19781","CVE-2020-5902","CVE-2021-26855","CVE-2021-44228","CVE-2023-22515","CVE-2024-24919","CVE-2024-8190","CVE-2024-8963","CVE-2024-9380","CVE-2025-31161","CVE-2026-1731"],"inTheWild":true,"confidence":0.88,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"The Hacker News","sourceHomepage":"https://thehackernews.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"3ca3c0010c19da22d5141b557bd77f10bedbd192","sourceId":"cyberscoop","url":"https://cyberscoop.com/collective-cyber-defense-letter-vendor-questionnaire-op-ed/","title":"The Collective Cyber Defense letter wrote your next vendor questionnaire","author":"@gregotto","publishedAt":1788256800000,"fetchedAt":1789019659430,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://cyberscoop.com/wp-content/uploads/sites/3/2026/08/GettyImages-2274897069.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789021592135,"category":"industry","severity":"info","importance":28,"tldr":"Op-ed argues the 200-company Collective Cyber Defense letter's three endorsed metrics should become standard vendor procurement questions.","summary":"More than 200 companies including Microsoft, Google, AWS, CrowdStrike, Anthropic and Okta signed an August 27 open letter calling for faster cyber defenses against AI-enabled attacks. The letter endorses three measurable metrics: coverage, containment speed, and verified remediation. The author turns those into five concrete procurement questions buyers should pose at vendor renewals, while noting the letter contains no deadlines, dollar figures or measurable targets.","keyPoints":["Over 200 vendors and buyers signed the Collective Cyber Defense letter","CrowdStrike data: 88% of PoC-exploited vulns attacked within 48 hours","Letter endorses coverage, containment speed and remediation-verification metrics","Author proposes five renewal questions to hold signatories accountable","Signatories sell AI defense products into the same budget the letter expands"],"tags":["collective cyber defense","ai","procurement","crowdstrike","opinion","policy"],"entities":{"malware":[],"vendors":["Microsoft","Google","AWS","Cisco","IBM","CrowdStrike","Cloudflare","Anthropic","Okta","Fortinet"],"victims":["Mastercard","Visa","Capital One"],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.85,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"CyberScoop","sourceHomepage":"https://cyberscoop.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"0278277cc77d7525864d720513f035c6bb64781b","sourceId":"cyberscoop","url":"https://cyberscoop.com/watershed-250-texas-water-cybersecurity-pilot/","title":"‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help","author":"@timstarks","publishedAt":1788207673000,"fetchedAt":1789019659430,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://cyberscoop.com/wp-content/uploads/sites/3/2026/08/GettyImages-2211302831.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789021592135,"category":"policy-legal","severity":"info","importance":48,"tldr":"White House launches Watershed 250, a six-month Texas pilot using volunteer vendor cyber and AI tools to harden water utility defenses.","summary":"The Office of the National Cyber Director and Texas Cyber Command will oversee the six-month Project Watershed 250 pilot to improve water sector cybersecurity through industry-donated red teaming, system hardening and AI tooling. Twelve companies including Microsoft, Fortinet, Google Cloud, Palo Alto Networks, AWS, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos participated in the rollout. Officials cited recent attacks including an Iranian-backed campaign against 30 water systems in 12 states and a 2024 incident in Muleshoe, Texas. Some water-security professionals criticized the program as lacking dedicated funding.","keyPoints":["Six-month pilot overseen by ONCD and Texas Cyber Command in Texas.","A dozen vendors contribute red teaming, hardening and AI-based tooling.","Motivated by Iranian-linked attacks on 30 water systems across 12 states.","Contrasts with Biden-era EPA audit rule withdrawn after state lawsuits.","Scale-up of proven solutions nationally is planned after lessons learned."],"tags":["water-sector","critical-infrastructure","policy","oncd","texas","public-private-partnership"],"entities":{"malware":[],"vendors":["Microsoft","Fortinet","Google Cloud","Palo Alto Networks","AWS","Cloudflare","Zscaler","Forescout","Abnormal AI","Dragos"],"victims":[],"products":[],"ai_models":[],"countries":["United States"],"organizations":["Office of the National Cyber Director","Texas Cyber Command","EPA"],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.8,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"CyberScoop","sourceHomepage":"https://cyberscoop.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"bcc1338ae8aa6da5dfa9b1efc7907da419712c58","sourceId":"helpnetsecurity","url":"https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/","title":"PaperCut NG/MF vulnerabilities exploited in zero-day attacks","author":"@zeljkazorz","publishedAt":1788187182000,"fetchedAt":1789020711098,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://img.helpnetsecurity.com/wp-content/uploads/2023/04/25121028/papercut-25042023-02.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789021592135,"category":"exploit","severity":"high","importance":75,"tldr":"PaperCut warns of active zero-day exploitation chaining CVE-2026-81578 and CVE-2026-82078 for pre-auth remote code execution in NG/MF print management.","summary":"PaperCut Software confirmed attackers are chaining two vulnerabilities in PaperCut NG and MF: CVE-2026-81578, an improper access control flaw in the web management interface allowing unauthenticated configuration changes, and CVE-2026-82078, unsafe dynamic class loading in database connection utilities enabling arbitrary Java bytecode execution. Huntress reproduced a pre-authentication remote configuration takeover and full RCE chain against PaperCut NG 25.0.11.75758 and observed limited exploitation at two customers, including post-exploitation whoami and ver commands. The vendor released Emergency Patch Release 2 with additional hardening and urged restricting Application Server web access to trusted IPs. In 2023, Clop and LockBit affiliates abused CVE-2023-27350 and CVE-2023-27351 in the same software.","keyPoints":["CVE-2026-81578 allows unauthenticated config changes; CVE-2026-82078 enables bytecode execution.","Huntress reproduced pre-auth RCE chain against stock PaperCut NG 25.0.11.75758.","Emergency Patch Release 2 issued; install even if the first patch was applied.","Vendor urges restricting Application Server web interfaces to trusted internal IPs.","Clop and LockBit exploited PaperCut CVE-2023-27350/27351 in 2023."],"tags":["papercut","zero-day","rce","print-management","huntress","watchtowr","patch"],"entities":{"malware":[],"vendors":["PaperCut Software","Huntress","watchTowr"],"victims":[],"products":["PaperCut NG","PaperCut MF"],"ai_models":[],"countries":[],"organizations":[],"threat_actors":["Clop","LockBit"]},"cves":["CVE-2026-81578","CVE-2026-82078","CVE-2023-27350","CVE-2023-27351"],"inTheWild":true,"confidence":0.9,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"Help Net Security","sourceHomepage":"https://www.helpnetsecurity.com","clusterSize":0,"clusterLatestAt":null,"matched":["actor:LockBit"]},{"id":"d88855307b6e205eab1d6caae47b40a1fc9e41c6","sourceId":"cyberscoop","url":"https://cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/","title":"Officials disrupt Chinese espionage operation that hit multiple federal agencies","author":"@CyberScoopNews","publishedAt":1787772907000,"fetchedAt":1789019659430,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://cyberscoop.com/wp-content/uploads/sites/3/2026/04/GettyImages-1332529886.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789021592135,"category":"threat-actor","severity":"high","importance":88,"tldr":"FBI and DOJ seized QTFY infrastructure, disrupting a Chinese state-sponsored group that compromised federal agencies and critical infrastructure since 2018.","summary":"Authorities seized three domains powering QScan and QTRouter, the hacking suite of QTFY, a Chinese government-funded group operating through front company Nanjing Xinjiuwei Network Technology. Targets include the Departments of Energy, Justice, and Health and Human Services, the Federal Reserve, NASA, NIH, financial institutions, defense contractors, utilities, telecoms, and hospitals; the group exploited zero-days in Ivanti, Pulse Secure, Fortinet, Citrix, and others, intruding three DOE national labs in September 2024. QScan carried over 200 proof-of-concept exploits and processed more than two million scanning tasks in a single day in 2024.","keyPoints":["QTFY exploited Ivanti zero-days in September 2024 to hit DOE national labs, NIH, and HHS","QScan reconnaissance tool included 200+ PoC exploits; 2M+ tasks processed in one day","Group includes former PLA members and ran undetected for more than eight years","Joint FBI, NSA, and Cyber National Mission Force advisory released with indicators of compromise"],"tags":["qtfy","china","espionage","fbi","ivanti","qscan","botnet","critical-infrastructure"],"entities":{"malware":[],"vendors":["Ivanti","Pulse Secure","Fortinet","Citrix","Microsoft","F5","Check Point","BeyondTrust","Lumen Technologies"],"victims":["Department of Energy","Federal Reserve","NASA","NIH","Health and Human Services"],"products":["QScan","QTRouter"],"ai_models":[],"countries":["China","United States"],"organizations":["FBI","U.S. Department of Justice","NSA","Black Lotus Labs","Nanjing Xinjiuwei Network Technology"],"threat_actors":["QTFY"]},"cves":[],"inTheWild":true,"confidence":0.92,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"CyberScoop","sourceHomepage":"https://cyberscoop.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"5c37ef3fe1d8fe4e9db52dda96e2d12dea7c506a","sourceId":"securityaffairs","url":"https://securityaffairs.com/197873/apt/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure.html","title":"FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure","author":"@securityaffairs","publishedAt":1787765599000,"fetchedAt":1789020727870,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://i0.wp.com/securityaffairs.com/wp-content/uploads/2026/08/image-79.png?fit=848%2C569&ssl=1","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789021592135,"category":"threat-actor","severity":"high","importance":78,"tldr":"FBI seizes China-linked QScan and QTRouter hacking platforms used by QTFY to obfuscate intrusions against US federal agencies.","summary":"The DOJ and FBI seized domains hard-coded into QScan and QTRouter, two platforms operated by China-based Nanjing Xinjiuwei Network Technology Company on behalf of state-sponsored group QTFY. QScan automatically infected thousands of IoT devices which were added to QTRouter, an obfuscation network routing malicious traffic through compromised and proxy devices outside China. Targets included NASA, the Federal Reserve, Departments of Energy, Justice, and HHS, NIH, and the US Senate, exploiting flaws in Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange, F5 BIG-IP, Log4j, and others.","keyPoints":["FBI seized hard-coded domains, making both platforms inoperable","QScan infected thousands of IoT devices for QTRouter proxy net","Victims include NASA, Federal Reserve, DOJ, Senate, HHS","Exploited Fortinet, Citrix, Exchange, F5, Log4j flaws","Lumen described QTFY as a 'digital quartermaster'"],"tags":["qtfy","qscan","qtrouter","china","iot","botnet","critical infrastructure","fbi"],"entities":{"malware":["web shells","remote-access trojans"],"vendors":["Fortinet","Citrix","Microsoft","F5","Apache","Atlassian","Check Point","CrushFTP","Ivanti","BeyondTrust"],"victims":["NASA","Federal Reserve","Department of Energy","Department of Justice","HHS","NIH","US Senate"],"products":["Fortinet SSL-VPN","Citrix ADC","Microsoft Exchange","F5 BIG-IP","Log4j","Confluence","Ivanti appliances"],"ai_models":[],"countries":["China","US"],"organizations":["FBI","DOJ","Lumen","Black Lotus Labs","Ministry of State Security","PLA"],"threat_actors":["QTFY"]},"cves":[],"inTheWild":true,"confidence":0.9,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"Security Affairs","sourceHomepage":"https://securityaffairs.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"4b73b39eae8f7aab8cf4d73e00b1e9923c0032a2","sourceId":"tenable","url":"https://www.tenable.com/blog/edge-infrastructure-under-siege","title":"Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter","author":"Research Special Operations","publishedAt":1787749200000,"fetchedAt":1788880415389,"feedSummary":"A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.\nIt is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on…","contentStatus":"skipped","imageUrl":"https://www.tenable.com/sites/default/files/images/blog/eb14ceba-054f-4426-a6b4-1a2a2314ada8.png","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1788884790926,"category":"threat-actor","severity":"high","importance":62,"tldr":"Joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs shows nation-state and criminal groups independently converge on the same edge infrastructure.","summary":"Tenable and SentinelOne jointly analyzed 93 CVE-actor attribution pairs covering exploitation of perimeter devices. The data shows state-sponsored and financially motivated actors independently target the same edge products from Ivanti, Fortinet, and Palo Alto Networks. The findings challenge the narrative that edge exploitation is exclusively a China-nexus nation-state problem, showing a broader shared attack surface.","keyPoints":["93 CVE-actor attribution pairs analyzed","State and criminal actors hit the same edge devices","Ivanti, Fortinet, Palo Alto Networks edge products targeted","Edge exploitation is not solely a nation-state problem"],"tags":["tenable","sentinelone","edge-devices","exploitation","attribution","ivanti","fortinet","palo-alto-networks"],"entities":{"malware":[],"vendors":["Tenable","SentinelOne","Ivanti","Fortinet","Palo Alto Networks"],"victims":[],"products":["Ivanti edge products","Fortinet edge products","Palo Alto Networks edge products"],"ai_models":[],"countries":["China"],"organizations":["Tenable","SentinelOne"],"threat_actors":[]},"cves":[],"inTheWild":true,"confidence":0.6,"clusterId":null,"extra":{"hint":"vulnerability","source_weight":1},"sourceName":"Tenable Blog","sourceHomepage":"https://www.tenable.com/blog","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"d711349154903fa28b836b215d5bd5470d9d547a","sourceId":"helpnetsecurity","url":"https://www.helpnetsecurity.com/2026/06/18/eset-gentlemen-edr-killers/","title":"GentleKiller targets more than 400 security processes across 48 products","author":"@helpnetsecurity","publishedAt":1787545335000,"fetchedAt":1789020711098,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://img.helpnetsecurity.com/wp-content/uploads/2026/03/09194120/laptop-danger-1500.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789022923481,"category":"ransomware","severity":"high","importance":68,"tldr":"ESET details the Gentlemen ransomware gang's in-house GentleKiller EDR-killer framework targeting over 400 security processes across 48 products, supplied to affiliates.","summary":"ESET analyzed the Gentlemen ransomware gang's in-house GentleKiller EDR-killer framework, confirmed through an internal data leak from May 2026. The framework has at least eight variants impersonating legitimate security products and abusing vulnerable or malicious kernel drivers, targeting more than 400 process names across 48 security products. Gentlemen emerged in late 2025, became one of the five most active ransomware gangs in Q1 2026, offers affiliates a 90% ransom share, and practices double extortion using Go-based and C-based ESXi encryptors. The suite also reuses outside tools including HexKiller, ThrottleBlood, and HavocKiller, unified by a shared evasion layer that mimics well-known security vendors.","keyPoints":["Eight GentleKiller variants each impersonate a different product and abuse a different vulnerable kernel driver.","Victim selection rests centrally on the target's FortiGate firewall configuration.","Gang folded recently disclosed BYOVD PoCs (UnknownKiller, PoisonKiller) into tooling within days.","Victims concentrated in Southeast Asia, South America, and Western Europe rather than the U.S."],"tags":["gentlemen","gentlekiller","ransomware","edr-killer","byovd","eset","raas","masquerading"],"entities":{"malware":["GentleKiller"],"vendors":["ESET","Fortinet","Group-IB"],"victims":[],"products":["GentleKiller","HexKiller","ThrottleBlood","HavocKiller","FortiGate"],"ai_models":[],"countries":["Thailand","Brazil","France"],"organizations":["ESET","Group-IB"],"threat_actors":["Gentlemen","Qilin","Warlock","MedusaLocker","DragonForce","RansomHub"]},"cves":[],"inTheWild":true,"confidence":0.7,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"Help Net Security","sourceHomepage":"https://www.helpnetsecurity.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"ca382dbf522adc759416503254b62c7c982ac6db","sourceId":"therecord","url":"https://therecord.media/us-bank-says-breach-claims-related-to-fourth-party-incident","title":"U.S. Bank says breach claims related to fourth","author":null,"publishedAt":1787329288184,"fetchedAt":1789019655286,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://cms.therecord.media/uploads/us_bank_8375cf38fc.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789022923481,"category":"ransomware","severity":"low","importance":55,"tldr":"LockBit claimed data theft from U.S. Bancorp, but the bank attributes it to a fourth-party breach at a contractor's third party, with no impact on its own systems.","summary":"LockBit added U.S. Bancorp to its leak site and threatened to release stolen data within two weeks, but the bank investigated and attributed the claims to a fourth-party incident outside its environment. U.S. Bancorp stated there is no evidence its systems, networks, or data repositories were compromised and reported the matter to law enforcement. The bank is the seventh largest in the United States, and LockBit provided no samples to substantiate the claim. The gang, previously subject to a 2024 law enforcement takedown, earned $252.4 million in ransoms through 353 attacks from 2022 to 2024 according to the U.S. Treasury.","keyPoints":["LockBit listed U.S. Bancorp with two-week leak deadline","Bank attributes breach to fourth-party contractor incident","No evidence of compromise in U.S. Bancorp's own environment","LockBit previously subject to 2024 law enforcement takedown"],"tags":["lockbit","u.s. bancorp","ransomware","fourth party","leak site"],"entities":{"malware":[],"vendors":[],"victims":["U.S. Bancorp"],"products":[],"ai_models":[],"countries":["United States"],"organizations":["U.S. Treasury Department"],"threat_actors":["LockBit"]},"cves":[],"inTheWild":false,"confidence":0.9,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"The Record","sourceHomepage":"https://therecord.media","clusterSize":0,"clusterLatestAt":null,"matched":["actor:LockBit"]},{"id":"8f1c1a066453fbb0a8e0d0d8989fda95c02c1dbb","sourceId":"helpnetsecurity","url":"https://www.helpnetsecurity.com/2026/08/19/medusa-ransomware-cisa-warning/","title":"Medusa ransomware gang has hit over 500 organizations, CISA warns","author":"@helpnetsecurity","publishedAt":1787097600000,"fetchedAt":1789020711098,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://img.helpnetsecurity.com/wp-content/uploads/2024/08/27131517/ransomware-keyboard.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789022923481,"category":"ransomware","severity":"high","importance":75,"tldr":"FBI, CISA, and HHS warn Medusa ransomware has hit over 500 organizations across critical infrastructure since June 2021, using phishing and unpatched flaws.","summary":"An updated joint advisory from CISA, FBI, and HHS states Medusa ransomware has affected more than 500 organizations, spanning healthcare, defense, manufacturing, government, IT, financial services, education, insurance, and legal sectors. Since early 2023 Medusa has operated a ransomware-as-a-service affiliate model and buys access from initial access brokers for $100 to $1 million. Affiliates gain entry via phishing and unpatched internet-facing software, exploiting newly disclosed flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust within 24 hours. The group runs double extortion, giving victims 48 hours before leak-site publication, with $10,000 in cryptocurrency buying a one-day delay.","keyPoints":["Joint CISA/FBI/HHS advisory update covers 500+ Medusa victims since June 2021, including healthcare, defense, manufacturing, and finance.","Medusa moved to a RaaS affiliate model in early 2023 and buys access from brokers for $100 to $1 million.","Affiliates exploit newly disclosed flaws in ScreenConnect, Fortinet EMS, GoAnywhere, and BeyondTrust within 24 hours.","Uses PowerShell, Mimikatz, AnyDesk; gaze.exe encrypts files with .medusa extension after stopping backup and security services.","Double extortion: 48-hour deadline, leak-site countdown; $10,000 in crypto buys a one-day extension."],"tags":["medusa","ransomware","raas","cisa","fbi","critical-infrastructure","double-extortion","initial-access-brokers"],"entities":{"malware":[],"vendors":["ScreenConnect","Fortinet","Fortra","BeyondTrust"],"victims":[],"products":["AnyDesk","SimpleHelp"],"ai_models":[],"countries":[],"organizations":["CISA","FBI","HHS"],"threat_actors":["Medusa"]},"cves":[],"inTheWild":true,"confidence":0.75,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"Help Net Security","sourceHomepage":"https://www.helpnetsecurity.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"2c7a42a1fb495f9f7b32ad2f725b818116b0c950","sourceId":"securityaffairs","url":"https://securityaffairs.com/197434/malware/new-mirai-based-evooo1bot-botnet-targets-linux-devices.html","title":"New Mirai-Based Evooo1Bot Botnet Targets Linux Devices","author":"@securityaffairs","publishedAt":1787037615000,"fetchedAt":1789020727870,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://i0.wp.com/securityaffairs.com/wp-content/uploads/2026/08/image-50.png?fit=627%2C316&ssl=1","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789024964796,"category":"malware","severity":"medium","importance":45,"tldr":"FortiGuard Labs disclosed Evooo1Bot, a Mirai-based Linux botnet active since July 2026 that hijacks routers and IoT devices for DDoS, credential theft, and SOCKS5 proxying.","summary":"Fortinet's FortiGuard Labs disclosed Evooo1Bot, a previously undocumented Linux botnet active since July 2026 that reuses Mirai's DDoS engine while adding encrypted C2, SSH brute-force scanning, credential sniffing, and SOCKS5 proxy modules. The bot exploits 18 known CVEs across Alcatel, NETGEAR, Tenda, D-Link, Telesquare, and Mitsubishi devices, some dating back to 2007, and communicates exclusively over port 443 to blend with HTTPS traffic. Compromised hosts can be turned into SOCKS5 relays for anonymous traffic forwarding or monetization via proxy services. The malware uses AES-256-CTR, ChaCha20, and XOR obfuscation with a 28-command administration interface.","keyPoints":["Exploits 18 known CVEs across routers, cameras, and edge devices, opportunistically targeting unpatched firmware","SOCKS5 module supports direct listening mode and reverse relay mode for proxy infrastructure","Intercepts HTTP Basic Auth credentials and cookies passing through infected devices","Encrypted C2 over port 443 blends with normal HTTPS traffic"],"tags":["evooo1bot","mirai","botnet","ddos","iot","linux","socks5-proxy","fortinet"],"entities":{"malware":["Evooo1Bot","Mirai"],"vendors":["Fortinet"],"victims":[],"products":["Alcatel OmniPCX","NETGEAR Routers","Tenda Routers","D-Link Routers","Telesquare Devices","Mitsubishi ME-RTU"],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2007-3010","CVE-2016-6277","CVE-2018-14558","CVE-2019-14931","CVE-2020-10987","CVE-2021-46422","CVE-2022-37055","CVE-2024-29269","CVE-2025-10123","CVE-2025-55583"],"inTheWild":true,"confidence":0.92,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"Security Affairs","sourceHomepage":"https://securityaffairs.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"94401e3a9e83ec114178b827dd3d701c3b0645ef","sourceId":"thehackernews","url":"https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html","title":"Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies","author":"@TheHackersNews","publishedAt":1786958995000,"fetchedAt":1789019629127,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIDrkyaW1magTuvTfLfkhtk_8stt1zYUxgonTZX1yaI_OGxsGMV9wCRE8bglbRubclVma7bkghEbmah6ku4T2ZVnpSngl6k5Cw0iCXgNNpuy6I2ZNPQOYYIfqKNgcVQxkqZdgvFLLM82bK1By0hrAm4i9slLnFQwQmwLmpR8I9eb8Paze2sf2UJMlol81Q/s1700-nu-rw-lo-l85-e365/linux-botnet.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789024964796,"category":"malware","severity":"medium","importance":55,"tldr":"Fortinet researchers documented Evooo1Bot, a new Mirai-derived Linux botnet active since July 2026 that exploits known edge-device flaws to build SOCKS5 proxy networks.","summary":"Fortinet FortiGuard Labs identified Evooo1Bot, a previously undocumented Linux botnet built on the leaked Mirai source code, active in the wild since July 2026 and targeting internet-facing edge devices. It exploits numerous known CVEs in routers and devices from D-Link, Tenda, Telesquare, Zyxel, Hikvision, Atlassian Confluence, WSO2, TP-Link, NETGEAR, and others, delivering a bot binary via a wget.sh loader from 91.92.40.118 that clears bash history. The bot offers encrypted C2 on port 443, SSH brute-force scanning, credential sniffing, DDoS over DNS/TCP/UDP, an HTTP exploit dispatcher, and converts infected hosts into SOCKS5 proxies for anonymizing follow-on operations.","keyPoints":["Derived from leaked Mirai source code, extended with encrypted C2, SSH brute-force scanner, and SOCKS relay module","Exploits known CVEs in D-Link, Tenda, Telesquare, Zyxel, Hikvision, Confluence, WSO2, TP-Link, and more","Turns routers, firewalls, and cameras into SOCKS5 proxies to disguise traffic and reach internal networks","Loader script wipes bash history; binary checks for sandboxes and blends C2 into HTTPS on port 443","Supports DDoS attacks over DNS, TCP, and UDP plus persistence, file transfer, and interactive shell commands"],"tags":["evooo1bot","mirai","linux-botnet","socks5-proxy","ddos","fortinet","edge-devices","cve-exploitation"],"entities":{"malware":["Evooo1Bot","Mirai"],"vendors":["Fortinet","FortiGuard Labs","D-Link","Tenda","Telesquare","Zyxel","Hikvision","Atlassian","WSO2","TP-Link"],"victims":[],"products":["DIR-823X","DIR-868L B1","AC7","AC9","AC10","AC15","SDT-CW3B1","TLR-2005KSH"],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2007-3010","CVE-2016-6277","CVE-2018-14558","CVE-2019-14931","CVE-2020-10987","CVE-2021-36260","CVE-2021-46422","CVE-2022-26134","CVE-2022-29464","CVE-2022-30525","CVE-2022-37055","CVE-2023-1389","CVE-2024-29269","CVE-2024-4577","CVE-2024-10914","CVE-2025-10123","CVE-2025-1974","CVE-2025-55583"],"inTheWild":true,"confidence":0.85,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"The Hacker News","sourceHomepage":"https://thehackernews.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]},{"id":"0cd9e8e856c27fc56203c36d4a963b2d0cf8b8b3","sourceId":"helpnetsecurity","url":"https://www.helpnetsecurity.com/2026/08/17/fortinet-virtue-ai-acquisition/","title":"Fortinet expands AI security portfolio with Virtue AI acquisition","author":"@helpnetsecurity","publishedAt":1786924800000,"fetchedAt":1789020711098,"feedSummary":null,"contentStatus":"ok","imageUrl":"https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3-flash","aiAt":1789024964796,"category":"industry","severity":"info","importance":45,"tldr":"Fortinet acquired Virtue AI to add agent red-teaming, MCP scanning and runtime guardrails to its AI security portfolio.","summary":"Fortinet acquired Virtue AI to extend its Security for AI strategy beyond FortiAIGate, which protects LLMs from prompt injection, data leakage and model poisoning. Virtue AI brings automated agentic red-teaming across 50+ sandboxed environments and 14 domains, agent discovery and governance including MCP tool scanning, continuous AI validation, and real-time guardrails across text, images, video, audio and code. Financial terms were not disclosed and the consideration is immaterial to Fortinet; Gartner projects the AI security market to grow from $2.8B in 2026 to $16.4B by 2030.","keyPoints":["Automated red-teaming covers 50+ sandboxed environments, 14 domains and 1,000+ risk categories","Agent protection discovers unsanctioned AI apps, scans MCP tools and blocks malicious tool calls","Continuous validation generates audit-ready evidence across model updates and fine-tunes","Real-time guardrails enforce policies on content, jailbreaks and AI-generated code"],"tags":["fortinet","virtue-ai","acquisition","ai-security","agentic-ai","mcp","fortiaigate","llm"],"entities":{"malware":[],"vendors":["Fortinet","Virtue AI"],"victims":[],"products":["FortiAIGate","FortiGate Hyperscale Firewall","Fortinet Security Fabric","FortiGuard Labs"],"ai_models":[],"countries":[],"organizations":["Gartner"],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.75,"clusterId":null,"extra":{"archive":true,"source_weight":1,"published_unknown":false},"sourceName":"Help Net Security","sourceHomepage":"https://www.helpnetsecurity.com","clusterSize":0,"clusterLatestAt":null,"matched":["vendor:Fortinet"]}],"serverTime":1789507399552}