< ciso
brief />
Tag Banner

All news with #fortinet tag

252 articles

Key Takeaways from the Fortinet SASE Summit 2026

🛡️ At the SASE Summit 2026, industry and Fortinet experts explored how AI, unified networking and security, and sovereignty requirements are shaping the future of SASE. Speakers emphasized the need to secure new AI-driven users and agents, integrate networking, identity, and security under a common architecture, and provide flexible sovereign deployment options. The summit framed these trends around a new model of autonomous trust.
read more →

FBI and Secret Service Warn of Ongoing FortiBleed

🔒 The FBI and US Secret Service warned administrators to harden Fortinet FortiGate firewalls and SSL VPN gateways after reporting the persistent FortiBleed campaign. Agencies cited SOCRadar data indicating 86,644 compromised devices across 194 countries and linked ransomware affiliates to use of stolen credentials. The notice details attacker techniques including credential stuffing, GPU-accelerated cracking, and creation of administrative accounts to maintain stealthy persistence. Organizations are urged to isolate affected hosts, perform threat hunting, reset credentials, enable phishing-resistant MFA, and follow CISA eviction guidance.
read more →

CISA Endorses Cyber Decoys; FortiDeceptor 6.3

🛡️ CISA published guidance on Using Cyber Decoys to Strengthen Detection and Response, urging an assume-breach posture and use of honeypots, honeytokens, breadcrumbs, and tripwires. FortiDeceptor implements these concepts with decoy VMs, centralized lure management, and integration with the Fortinet Security Fabric. Version 6.3 expands decoy coverage to GitLab, IoT printers, and cloud connectors for S3, GitHub, and SharePoint, and supports automated response workflows.
read more →

Weekly Recap: NetScaler, FortiMail, and Major Threats

📰 This week’s recap highlights multiple actively exploited vulnerabilities, high-profile arrests, and evolving malware techniques that take advantage of small oversights. Notable items include Citrix NetScaler and FortiMail zero-days, arrests tied to ShinyHunters and KillSec operations, and novel attack methods like RedFlick delivering the CosmicPulse backdoor. The report stresses urgent patching and improved basic hygiene to reduce exposure.
read more →

Critical FortiMail Path Traversal Zero‑Day Alert

🔒 The U.S. CISA has added a critical Fortinet FortiMail flaw (CVE-2026-104286, CVSS 9.8) to its KEV catalog after reports of active exploitation. The vulnerability allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests due to path traversal and NULL byte handling issues. Fortinet has identified affected FortiMail versions and provided upgrade guidance and temporary workarounds, including disabling IBE and restricting management access.
read more →

Critical FortiMail Zero-Day Allows Remote Code Execution

🚨 Fortinet warns of a critical FortiMail vulnerability (CVE-2026-104286) actively exploited in zero-day attacks that can allow unauthenticated attackers to write arbitrary files and execute code via crafted HTTP/HTTPS requests. The flaw affects multiple FortiMail 7.x and 8.0 releases; Fortinet identified the issue internally and provided temporary workarounds while patches are prepared. Admins are urged to disable IBE support or block management access from the Internet and to check published IOCs and logs for signs of compromise.
read more →

Building a Security-First Culture Amid Rapid Threats

🔒 The accelerating threat landscape driven by AI and automation is compressing exploit windows and amplifying attacker efficiency, making basic cyber hygiene essential. Fortinet’s research highlights faster time-to-exploit and the maturation of a criminal supply chain offering credentials, malware, and services. Embedding routine protective behaviors—like MFA, patching, and timely reporting—into daily operations strengthens resilience and reduces attacker opportunities.
read more →

Cloud Intrusions Escalate to Machine-Speed Threats

🔍 The 2026 Cloud-Native Threat Landscape Report, based on FortiCNAPP intelligence, shows that adversaries are automating cloud attacks to find, exploit, and monetize vulnerabilities at unprecedented speed. The report documents billions of reconnaissance, brute-force, and exploitation attempts and stresses that identity compromise and misconfigurations remain prime intrusion vectors. It urges security teams to adopt AI-driven, automated defenses across the entire application lifecycle to detect and respond at machine speed.
read more →

Sovereign AI and Quantum-Ready Defense with FortiNDR

🛡️ Fortinet expands its NDR portfolio with FortiNDR Cloud and on‑prem FortiNDR, adding dynamic deception, a post‑quantum cryptography (PQC) dashboard, and an on‑premises AI investigation capability. The PQC dashboard surfaces quantum‑vulnerable encryption from network traffic without new agents, while dynamic deception integrates with FortiDeceptor and Fortinet Automation Service to misdirect attackers. FortiAI Sovereign provides AI‑driven investigation fully within air‑gapped environments, eliminating cloud dependence.
read more →

Critical Pre‑Auth RCE in Orkes Conductor Actively Exploited

🛡️ Fortinet and other telemetries report active exploitation of CVE-2026-58138, a critical unauthenticated remote code execution flaw in Orkes Conductor. The vulnerability affects versions 3.21.21 through 3.30.1 and allows attackers to execute arbitrary OS commands by submitting crafted workflow definitions containing JavaScript or Python expressions to the workflow API. Exploits leverage unsandboxed GraalVM evaluators with unrestricted host access, and multiple vendors have observed in-the-wild attempts. Users are urged to upgrade to Conductor 3.30.2 or later and apply network mitigations if immediate patching is not possible.
read more →

SE Labs launches PIVOT test for vendor defences

🛡️ SE Labs has launched a six-month testing program called PIVOT to evaluate how effectively cybersecurity vendors defend against major nation-state and criminal threat groups. The program runs real-world attack chains from July through October in SE Labs’ London test lab and will publish verified results in January 2027. Participants include Broadcom (Symantec, Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks and Sophos. Gartner and Forrester analysts will independently verify the findings before publication.
read more →

From Intelligence to Disruption in Latin America

🛡️ The 11th Americas Working Group convened INTERPOL, the World Economic Forum, Paraguayan authorities, and public-private experts to explore how intelligence can enable operations against cybercrime in Latin America. Fortinet and FortiGuard Labs emphasized turning telemetry into actionable intelligence that supports investigations and coordinated disruption. The meeting highlighted the need for structured collaboration, real-time sharing, and sustained capability building to raise the cost for cybercriminals.
read more →

CISA Adds Cisco, Citrix, Fortinet Flaws to KEV List

🔒 CISA has added three critical vulnerabilities affecting Cisco, Citrix, and Fortinet to its Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to patch by September 12, 2026. The issues include a Cisco FMC authentication bypass (CVE-2026-20079, CVSS 10.0) with active exploitation, a Citrix NetScaler ADC/Gateway bypass (CVE-2026-19490, CVSS 9.3), and a Fortinet FortiOS heap overflow (CVE-2025-25249, CVSS 7.3) linked to a Node.js RAT called PivotC2. Vendors and researchers reported observed post-compromise activity, honeypot hits, and large-scale scanning campaigns, prompting guidance to patch, limit internet exposure, and hunt for indicators of compromise.
read more →

Fortinet Joins Project Watershed to Secure Water Systems

💧Fortinet joined federal, state, and industry partners on August 31 to launch Project Watershed 250, a six-month pilot in Texas aimed at strengthening water and wastewater cybersecurity. The program offers participating utilities red-team testing, system assessments, hardening support, threat intelligence, and AI-enabled defenses. It emphasizes proactive, scalable public-private collaboration to protect OT environments and develop a model for broader national adoption.
read more →

Fortinet and FIRST Strengthen Global Cyber Resilience

🔒 Fortinet’s partnership with the Forum of Incident Response and Security Teams (FIRST) advances global cyber resilience by combining FortiGuard Labs’ threat intelligence with FIRST’s incident response network. CORE, a 2025 initiative co-founded by Fortinet, funds capacity building, regional training, and tabletop exercises to close skills gaps and improve cross-border coordination. This collaboration also supports standards like EPSS and CVSS to turn shared practices into operational defenses.
read more →

INTERPOL: Cybercrime Industrialization Threatens Africa

🔎 INTERPOL’s African Cyberthreat Assessment Report 2026, with contributions from FortiGuard Labs, finds cybercrime in Africa has shifted into an industrialized, borderless ecosystem driven by specialized service providers, shared infrastructure, automation, and AI. The report links rapid digital adoption to rising exploitation, noting reported losses doubled from 2024 to 2025 and credentials are often the initial foothold. It calls for integrated identity-centric defenses, faster intelligence-to-protection workflows, and stronger public-private collaboration to enable disruption.
read more →

Join the SASE Summit: Building Autonomous Trust

🛡️ Fortinet invites security and IT leaders to the 2026 SASE Summit, "The Age of Autonomous Trust," on September 15 and 17. Speakers include Gartner analysts and Fortinet experts discussing how AI, LLMs, agents, and distributed interactions reshape access, data movement, and policy enforcement. Sessions cover securing GenAI, extending trust to AI-driven activity, modernizing access beyond VPNs, and addressing sovereignty through Sovereign SASE deployments.
read more →

Gunra Ransomware Targets Critical Infrastructure Globally

🔒 Cybersecurity agencies in South Korea and the U.S. have warned of Gunra ransomware campaigns targeting critical infrastructure sectors globally, including healthcare, finance, and government. The actors exploit vulnerabilities in Schneider Electric PowerLogic P5 and Fortinet FortiOS/FortiProxy to gain access, then use double extortion tactics combining data theft and encryption. Victims face data leaks within days if ransoms are not paid.
read more →

FortiOS v7.6.x Achieves IEC 62443-4-2 SL4

🔒 Fortinet announces that FortiOS v7.6.x has achieved IEC 62443-4-2 Security Level 4 (SL4) certification, the highest component assurance level for industrial automation and control systems. This complements the company’s IEC 62443-4-1 ML2 accreditation for secure product development and validates FortiOS technical capabilities across identification, integrity, confidentiality, availability, and response requirements. The certification applies across FortiGate platforms running v7.6.x, reinforcing operational resilience for OT and critical infrastructure environments.
read more →

Fortinet and Crime Stoppers Launch Cybercrime Bounty

🛡️ The Cybercrime Bounty program from Crime Stoppers International and Fortinet has launched its first live bounty, Operation Silent Vector I, to identify individuals behind the INC ransomware group. The program combines anonymous reporting, threat validation by FortiGuard Labs, and established escalation to law enforcement, with potential financial rewards for actionable tips.
read more →