Over 10,000 Fortinet firewalls globally are still vulnerable to CVE-2020-12812, a flaw that allows bypassing multi-factor authentication (MFA) and was revealed over five years ago. Shadowserver added this issue to its daily Vulnerable HTTP Report. CVE-2020-12812 is due to inadequate authentication in FortiOS SSL VPN portals, impacting versions 6.4.0, 6.2.0 …
Read More »Fortinet Warns of 2020 FortiGate Flaw to Bypass 2FA
Fortinet warns that a three-year-old vulnerability allows attackers to bypass 2FA on FortiGate firewalls by merely altering the capitalization of usernames. The vulnerability FG-IR-19-283 (CVE-2020-12812) was reported and fixed in July 2020. Recently, it has been noted that attackers are exploiting this flaw in organizations that haven’t addressed specific configurations. …
Read More »Over 100 Cisco Secure Email Devices Exposed to Zero‑Day Attack
Security researchers found at least 120 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices vulnerable to a critical zero-day flaw that is being actively exploited. CVE-2025-20393 is a vulnerability with no patch available, putting organizations at risk. Threat intelligence from Shadowserver Foundation indicates that vulnerable devices …
Read More »Tool Unveil to Detect Cisco Secure Email Gateway 0-Day Vulnerability
A simple Python script to help organizations quickly detect exposure to CVE-2025-20393, a critical zero-day vulnerability in Cisco Secure Email Gateway (SEG) and Secure Malware Analytics (SMA). The “Cisco SMA Exposure Check” tool identifies open ports and services exploited in recent attacks, as noted in Cisco’s advisory. GitHub user StasonJatham …
Read More »ASRock, ASUS, GIGABYTE, MSI Motherboards New UEFI Flaw allow pre-boot attacks
Certain motherboards from ASUS, Gigabyte, MSI, and ASRock are susceptible to DMA attacks that can bypass early-boot memory protections. This security flaw has several identifiers (CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304)due to differences in vendor implementations. The vulnerability found by Nick Peterson and Mohamed Al-Sharifi of Riot Games in some UEFI …
Read More »1.7 Million Login Attempts Target Palo Alto and Cisco SSL VPNs in 16 Hours
GreyNoise reported that login attempts on GlobalProtect portals surged to 1.7 million over 16 hours, targeting various VPNs, including Palo Alto Networks GlobalProtect and Cisco SSL VPN. Data revealed that over 10,000 unique IP addresses targeted infrastructure in the United States, Mexico, and Pakistan. The malicious traffic originated almost entirely …
Read More »Alert: HPE (CVE-2025-37164) warns RCE flaw and ASUS (CVE-2025-59374) Flaw added in KEV
Hewlett Packard Enterprise (HPE) has fixed a critical vulnerability in its OneView software that allowed remote code execution. OneView is HPE’s software for managing infrastructure, helping IT admins streamline server, storage, and network management. Vietnamese researcher Nguyen Quoc Khanh (brocked200) reported the critical security flaw (CVE-2025-37164) to the company’s security …
Read More »CISA added Actively Exploited Apple WebKit 0-Day Flow
CISA has listed a critical zero-day vulnerability affecting various Apple products in its Known Exploited Vulnerabilities catalog, indicating it is being actively exploited. CVE-2025-43529 is a severe use-after-free vulnerability in WebKit, Apple’s rendering engine, affecting millions of users on iOS, iPadOS, macOS, and other Apple platforms. A use-after-free vulnerability (CWE-416) …
Read More »Critical FortiGate Vulnarability Under Active Attack
Threat actors started to exploit two critical flaws (CVE: 2025-59718 and CVE: 2025-59719 in Fortinet FortiGate devices. Unauthenticated attackers can exploit these vulnerabilities to bypass SSO login protections using crafted SAML messages when FortiCloud SSO is enabled on affected devices. December 12, 2025, Arctic Wolf identified coordinated attacks using malicious …
Read More »Apple Patches Two Critical WebKit Zero-Days Under Active Exploitation
Apple has urgently patched two critical zero-day vulnerabilities in the WebKit browser engine affecting iPhone and iPad users. The company revealed these flaws are actively exploited, enabling advanced attacks on high-risk targets. Vulnerabilities CVE-2025-43529 and CVE-2025-14174 let attackers run malicious code if a victim visits a specific web page. WebKit …
Read More »
InfoSecBulletin Cybersecurity for mankind