
FBI Warns of Ongoing FortiBleed Attacks Locking Out FortiGate VPN Admins
FBI warns of ongoing FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways, locking out legitimate administrators.
Stories tagged “Network Security.”
30 stories

FBI warns of ongoing FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways, locking out legitimate administrators.

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.

Attackers exploit MikroTik routers' SSH service to gain admin control without authentication, affecting devices with certain RouterOS versions.

Plex is urging users to update their instances to the latest version after releasing an update that patches multiple security flaws.

Cisco has issued patches for a critical vulnerability (CVE-2026-20212) in 10 Silicon One-based Nexus 9000 switches, allowing unauthenticated remote attackers to execute code as root.

Google's Android 17 update includes Encrypted Client Hello (ECH) to protect user privacy and hide website visits from network providers.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabil…

Cisco has published security updates for Crosswork platforms and Secure Workload Software, addressing nine vulnerabilities, including five with a CVSS score of 10.0. The issues affect Cisco Crosswork Release version 7.2.1 and earlier and have been addressed in version 7.2…

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.

CISA flags critical Ray flaw, citing active exploitation. CVE-2025-62593 can lead to remote code execution via web browsers like Firefox and Safari.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008.

A new attack class called NatJack has been disclosed by security researcher Malcolm Stagg. It manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.

Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.

A browser security gap has been exposed by AI, which enterprises cannot ignore. This gap is a result of employees moving sensitive data through browser-based applications, and AI has accelerated the volume and visibility of these interactions.

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, …

Cybersecurity researchers have discovered a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. The issue is rooted in three features in Apple's WebKit: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport.

cPanel has patched a critical flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity.

The INC Ransomware operation has emerged as the dominant threat actor exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Fixes for the vulnerability pair were released by SonicWall in mid-July 2026.

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete.

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.

Researchers have uncovered 84 security vulnerabilities in 4G and 5G core networks, stemming from "implicit trust errors" that could enable denial-of-service attacks and session hijacking.

A Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. The agent found internet-facing systems and selected public exploits after an initial Telegram instruction.

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. The attack caused a plant outage, communications failures, or affected automated controls in sever…

A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. Tengu supports 25 distributed denial-of-service (DDoS) methods and can also run a SOCKS5 proxy, execute shell commands,…

A critical command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation, allowing remote code execution and potential system compromise. Arista has released patches and provided indicators of compromise.

The Dysphoria IoT botnet has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The botnet's population is estimated to be above 200,000 bots, with 4,401 confirmed active devices insid…

Cybersecurity defenses are being outpaced by AI-equipped attackers, leading to a need for multi-layered network detections to contain and analyze post-compromise behavior.