Phorpiex Phishing Delivers Low-Noise Global Group Ransomware

High-volume phishing campaign delivers Phorpiex malware via malicious Windows Shortcut files - Read more

Yokogawa FAST/TOOLS

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to redirected users to malicious sites, decrypt communications, perform a man-in-the-middle (MITM) attack, execute...

XSS via back button

CVSSv3 Score: 7.9 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FortiSandbox may allow an...

Firewall policy bypass in FSSO Terminal Services Agent

CVSSv3 Score: 3.8 An Improper Verification of Source of a Communication Channel vulnerability in FortiOS FSSO Terminal Services Agent may...

CVE-2026-21519 Desktop Window Manager Elevation of Privilege Vulnerability

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. - Read more

Arbitrary XML file write in FCConfig

CVSSv3 Score: 6.4 An Improper Link Resolution Before File Access vulnerability in FortiClient Windows may allow a local low-privilege attacker...

SSL-VPN Symlink Persistence Patch Bypass

CVSSv3 Score: 5.3 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in FortiOS SSL-VPN may allow a remote...

Request smuggling attack in FortiOS GUI

CVSSv3 Score: 5.2 An HTTP request smuggling vulnerability in FortiOS may allow an unauthenticated attacker to smuggle an unlogged http...

Missing authorization on CSV user import

CVSSv3 Score: 6.8 A missing authorization vulnerability in FortiAuthenticator may allow a read-only admin to make modification to local users...

LDAP authentication bypass in Agentless VPN and FSSO

CVSSv3 Score: 7.5 An Authentication Bypass by Primary Weakness vulnerability in FortiOS fnbamd may allow an unauthenticated attacker to bypass...

Latest article

‘Agents of Chaos’: New Study Shows AI Agents Can Leak Data, Be Easily Manipulated

As enterprise AI agent adoption accelerates, a new study exposes a governance gap that leaves most organizations unable to stop their own systems The post...

Rapid7 Detection Coverage for Iran-Linked Cyber Activity

The tension arising out of the conflict in Iran is beginning to show signs of expanding beyond a strictly regional crisis. Following our recent...

France: National Cybersecurity Agency Reports Ransomware Attack Drop in 2025

French small and medium businesses remained the organizations most targeted by ransomware in 2025 - Read more

Stryker Cyber Attack – Hackers Claim System Breach and Device Wipe

On March 11, 2026, the global medical technology giant Stryker experienced a severe cyberattack when Iranian-linked hackers used wiper malware to permanently erase data...