Home Blog Page 60

Heap-based buffer overflow in oftpd daemon

CVSSv3 Score: 7.3 A heap-based buffer overflow vulnerability in FortiAnalyzer Cloud oftpd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation Revised on 2026-04-14 00:00:00 - Read more

Hardcoded symmetric encryption key for Postgresql

CVSSv3 Score: 5.2 A use of hard-coded cryptographic key vulnerability in FortiClientEMS may allow an attacker in possession of an encrypted dump of the database to decrypt it. Revised on 2026-04-14 00:00:00 - Read more

Credential disclosure in LDAP configuration web page.

CVSSv3 Score: 2.5 An Insufficiently protected credentials vulnerability in FortiSanbox and FortiSanbox PaaS GUI may allow an authenticated administrator to read LDAP server credentials via client-side inspection. Revised on 2026-04-14 00:00:00 - Read more

Cleartext Credentials in response for API endpoints

CVSSv3 Score: 6.2 A Cleartext Transmission of Sensitive Information vulnerability in FortiSOAR may allow an authenticated attacker to view cleartext password in response for Secure Message Exchange and Radius queries, if configured Revised on 2026-04-14 00:00:00 - Read more

Clear-text credentials retrievable with IP modification for connectors

CVSSv3 Score: 4.1 A Storing Passwords in a Recoverable Format vulnerability in FortiSOAR may allow an authenticated remote attacker to retrieve passwords for multiple installed connectors via server address modification in connector configuration. Revised on 2026-04-14 00:00:00 - Read more

Clear-text credentials retrievable with IP modification for LDAP

CVSSv3 Score: 4.1 A Storing Passwords in a Recoverable Format vulnerability in FortiSOAR may allow an authenticated remote attacker to retrieve Service account password via server address modification in LDAP configuration. Revised on 2026-04-14 00:00:00 - Read more

Axios npm Package Compromised

On March 31, 2026, the Axios npm package was compromised via a maintainer account takeover. Two malicious versions were published - axios@1.14.1 and axios@0.30.4 - which introduced a hidden dependency (plain-crypto-js@4.2.1) able to execute a post‑install script deploying a cross‑platform Remote Access Trojan (RAT) on Windows, macOS, and Linux systems. Revised on 2026-04-14 00:00:00 - Read...

Arbitrary directory delete on vmimages delete feature

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00 - Read...

2FA request can be replayed without a valid token after one successful request

CVSSv3 Score: 6.7 An Improper authentication vulnerability in FortiSOAR web GUI may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration. Revised on 2026-04-14 00:00:00 - Read more

A New Way to Buy Recorded Future: Solutions and Packages Built for the 2026 Threat Landscape

Recorded Future is now offering four solutions covering cyber operations, digital risk protection, third-party risk, and payment fraud. Three tiered packages (Core, Professional, Elite) bundle these solutions to scale with an organization's security program. Packages include unlimited users and integrations so intelligence reaches everyone who needs it. The global threat...

Latest article

GreatXML zero-day BitLocker bypass doesn’t seem to work, yet

A disgruntled researcher who has been publishing zero-day Microsoft Windows vulnerabilities for the past several months released a new exploit...

New Windows Zero-Day Claims BitLocker Bypass Amid Microsoft Disclosure Fight

A new Windows zero-day reportedly bypasses BitLocker, adding pressure on Microsoft as researchers debate the exploit’s real-world impact. The post New Windows Zero-Day Claims BitLocker...

Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks

One of the most persistent hacking groups in the world has found a new way to stay hidden. The threat actor known as...

Ransomware Payment Crypto Laundering Platform Taken Out by FBI and Europol

Domain of dark web money laundering platform AudiA6 seized and suspects arrested in joint operation by the FBI, Europol and others - Read...