< ciso
brief />
Tag Banner

All news with #fortinet tag

235 articles

Gunra Ransomware Targets Critical Infrastructure Globally

🔒 Cybersecurity agencies in South Korea and the U.S. have warned of Gunra ransomware campaigns targeting critical infrastructure sectors globally, including healthcare, finance, and government. The actors exploit vulnerabilities in Schneider Electric PowerLogic P5 and Fortinet FortiOS/FortiProxy to gain access, then use double extortion tactics combining data theft and encryption. Victims face data leaks within days if ransoms are not paid.
read more →

FortiOS v7.6.x Achieves IEC 62443-4-2 SL4

🔒 Fortinet announces that FortiOS v7.6.x has achieved IEC 62443-4-2 Security Level 4 (SL4) certification, the highest component assurance level for industrial automation and control systems. This complements the company’s IEC 62443-4-1 ML2 accreditation for secure product development and validates FortiOS technical capabilities across identification, integrity, confidentiality, availability, and response requirements. The certification applies across FortiGate platforms running v7.6.x, reinforcing operational resilience for OT and critical infrastructure environments.
read more →

Fortinet and Crime Stoppers Launch Cybercrime Bounty

🛡️ The Cybercrime Bounty program from Crime Stoppers International and Fortinet has launched its first live bounty, Operation Silent Vector I, to identify individuals behind the INC ransomware group. The program combines anonymous reporting, threat validation by FortiGuard Labs, and established escalation to law enforcement, with potential financial rewards for actionable tips.
read more →

Fortinet expands FortiGate with SASE-enabled 1200G

🔒 Fortinet introduced the midrange FortiGate 1200G series running FortiOS 8.0, offering 10G–100G connectivity and 397 Gbps firewall throughput for campus, data center, and hybrid environments. The appliances can operate as a local SASE POP via FortiSASE Outpost, extending cloud-managed policy enforcement, visibility, and zero-trust controls to on-premises sites while keeping logs and traffic within customer boundaries. Availability is slated for Q3 2026.
read more →

Security Awareness Shifts From External to Internal Risk

🔒 External threats still drive security training, but organizations increasingly focus on internal risks arising from everyday workflows, cloud apps, collaboration tools, and AI. The 2025 Fortinet Training Institute report shows rising attention to data security, privacy, and AI-related guidance, and finds practical, role-specific training is needed to reduce accidental exposures. Fortinet highlights integrating awareness, simulation, and assessment to build a resilient workforce.
read more →

Canada Signs UN Cybercrime Convention, Driving Cooperation

🛡️ Canada signed the UN Convention against Cybercrime to strengthen international cooperation on electronic evidence, mutual legal assistance, and capacity building. The treaty emphasizes 24x7 contact points, human-rights safeguards, and technical assistance for countries with limited cybercrime capabilities. Fortinet highlights the need for sustained public-private partnerships to operationalize the treaty and accelerate cross-border disruption.
read more →

Expert Density Strategy: 2F-IT’s Fortinet Focus

🔒 2F-IT has built a Fortinet-centric consultancy in Germany by concentrating senior NSE 8 expertise within a compact team. This approach embeds expert practitioners into delivery, mentorship, and architecture decisions, reducing reliance on single points of failure. The firm supports certification through labs, mentoring, and incentives, translating deep technical capability into higher quality, resilient customer outcomes across complex environments.
read more →

Practical Roadmap for Post‑Quantum Cryptography Readiness

🔒 The shift to Post‑Quantum Cryptography (PQC) is now a practical priority for security, architecture, procurement, and compliance teams. The White House EO sets firm federal deadlines for PQC adoption in 2030–2031 and prompts broader supply‑chain impacts, making 2026–2027 critical planning years. Organizations should inventory cryptographic dependencies, assess vendor readiness, prioritize systems vulnerable to “harvest now, decrypt later” threats, and build crypto‑agility. Fortinet tools like FortiManager, FortiAnalyzer, and FortiGate hardware acceleration support discovery, risk measurement, and targeted protection to help operationalize PQC migration.
read more →

Fortinet and Crime Stoppers Launch Cybercrime Bounty

🛡️ The interview outlines a partnership between Crime Stoppers International and Fortinet to create the Cybercrime Bounty program, a secure and anonymous channel for private-sector contributors to report suspected cybercriminals. It emphasizes anonymity, Fortinet’s threat-intelligence validation, and the program’s focus on identifying human actors and networks rather than software vulnerabilities. The initiative aims to turn tips into actionable intelligence for law enforcement and strengthen public–private cooperation to disrupt cybercrime at scale.
read more →

TrickBot shifts to DNS tunneling for C2 communications

🛡️ Fortinet researchers uncovered a TrickBot variant that abandons HTTP for a custom DNS tunneling C2 channel, embedding encrypted commands and payloads within malformed DNS queries. The modular malware uses single-byte XOR encoding, hex-encoding and 63-character domain chunking for outbound beacons, while inbound data hides in multiple IPv4 addresses returned by resolvers. Persistence relies on Windows Task Scheduler with NTFS ADS, and command handling retains prior modular capabilities for executing modules, DLLs, PowerShell and shellcode.
read more →

CISA urges immediate patching of Fortinet FortiSandbox

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) has added two critical FortiSandbox vulnerabilities, CVE-2026-39808 and CVE-2026-25089, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply patches by July 19. Both flaws are OS command injection bugs with CVSS scores of 9.1 and have documented in-the-wild exploitation. Fortinet released fixes in FortiSandbox versions 4.4.9 and 5.0.6; CISA advised discontinuing cloud services where mitigations are unavailable.
read more →

Fake TTF loader used in global phishing campaign

🛡️ Fortinet's FortiGuard Labs reports a global phishing campaign using obfuscated JavaScript and a Lua-based loader disguised as a TrueType Font (.ttf) to evade detection. The attack chain delivers RATs and infostealers such as Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant, employing in-memory execution and various anti-analysis techniques. Researchers noted business- and payment-themed lures, compressed archives with script loaders, and Donut shellcode to avoid writing payloads to disk. Defenders are advised to combine identity controls, application restrictions, and behavior-based detection.
read more →

CISA orders urgent FortiSandbox patches for agencies

🔒 CISA has ordered U.S. federal agencies to urgently patch two actively exploited critical vulnerabilities in the Fortinet FortiSandbox platform. The flaws (CVE-2026-39808 and CVE-2026-25089) were fixed by Fortinet in April and June, and allow unauthenticated remote command injection with low complexity. Defused and CISA confirmed in-the-wild exploitation, and agencies must remediate by Sunday, July 19. Administrators are advised to upgrade affected deployments to the latest released versions to block attacks.
read more →

The TTF Trap: Lua Loader Campaign Analysis

🔍 Since late March 2026, FortiGuard Labs documented a global phishing campaign that uses heavily obfuscated JScript droppers and AutoIt/Lua-based loaders disguised as .ttf files to deploy RATs and infostealers. Attackers impersonate reputable organizations to deliver malicious archives that stage multi-layered loaders with low detection rates. The campaign ultimately deploys payloads like Agent Tesla, Remcos, XWorm, and Snake-derived keyloggers, enabling remote control and data theft.
read more →

Fortinet and INTERPOL Strengthen Cybercrime Response

🔍 Fortinet reinforced its decade-long partnership with INTERPOL at the INTERPOL Partners’ Conference in Lyon, stressing the need for faster, trust-based intelligence sharing to counter AI-accelerated cybercrime. Panel discussions highlighted how AI and agentic systems amplify threats across phishing, fraud, and cybercrime-as-a-service while underscoring the role of FortiGuard Labs in supporting coordinated disruption. The piece calls for sustained public-private collaboration, shared detection methods, and resource support for global law enforcement.
read more →

Fortinet Unified SASE: Architecture Built for AI Era

🔒 Fortinet outlines why unified SASE must be genuinely integrated rather than assembled from disparate products. The company highlights AI-driven security, autonomous operations, and digital experience convergence as core innovations within its FortiOS-based platform. Fortinet emphasizes hardware acceleration with FortiASIC, sovereign deployment options, and consistent policy enforcement across cloud, edge, and on-premises environments. Customer recognitions and analyst placements are cited as validation of the platform’s maturity.
read more →

FortiBleed ties stolen Fortinet credentials to ransomware

🛡️ SOCRadar links the FortiBleed credential-theft campaign to the INC and Lynx ransomware operations after finding a Windows server used by FortiBleed that contained access to ransomware negotiation panels. Investigators discovered FortiGate configuration files, harvested credentials, and a custom "FortiGate Sniffer" tool that intercepted VPN and authentication data. The operation targeted hundreds of thousands of devices and deployed sniffers on thousands, with ongoing investigation into additional servers, a suspected Nextcloud zero-day, and overlapping victim data.
read more →

Ousaban banking trojan targets Spain and Portugal

🛡️ Fortinet's FortiGuard Labs uncovered a May 2026 campaign deploying the Brazilian banking trojan Ousaban against Windows users who bank in Spain and Portugal. The attack begins with a deceptive PDF that either prompts victims to click an "Atualizar" button or auto-opens a malicious page; successful targets download a steganographic image that conceals a ZIP containing the malware. Ousaban monitors browser activity for over two dozen Iberian banks and can capture keystrokes, screenshots, tamper with the clipboard, display fake messages, and grant remote control to attackers.
read more →

Fortinet Update on Frontier AI Use in Security

🔒 Fortinet describes its integration of frontier AI models (Anthropic’s Glasswing/Mythos and OpenAI’s Daybreak/GPT 5.5 Cyber) alongside on-premises models to scale security testing across firmware, source code, and penetration testing. The company emphasizes responsible innovation, mature vulnerability management, and human validation of AI findings. Fortinet reports limited exploitable firmware issues but greater findings from source-code analysis and commits to mitigation, virtual patching, and secure-by-default deployments.
read more →

Fortinet Supports INTERPOL Operation CyberProtect III

🔎 Fortinet contributed to INTERPOL’s Operation CyberProtect III by providing intelligence and analysis through its role in the World Economic Forum’s Cybercrime Atlas. The four-day initiative helped identify dozens of suspicious cases, suspect profiles, and potential victims on content subscription platforms. The operation highlighted trends such as encrypted messaging, coded language, cryptocurrency payments, and AI-generated profiles used to facilitate exploitation.
read more →