Thursday , October 8 2026
FortiBleed

FortiBleed Attack Compromised 80,000+ Devices, SonicWall Patches 4 SMA1000 Flaws CVSS 10

The FBI and U.S. Secret Service released a joint warning about cybersecurity. The warning said that the FortiBleed campaign is attacking Fortinet FortiGate firewalls and SSL VPN gateways around the world.

The operation that stole credentials has affected over 86,644 devices in 194 countries, putting organizations at great risk if they expose Fortinet management or remote-access services online.

FortiBleed Attack Compromised 80,000+ Devices, SonicWall Patches 4 SMA1000 Flaws CVSS 10

The FBI and U.S. Secret Service released a joint warning about cybersecurity. The warning said that the FortiBleed campaign is...
Read More
FortiBleed Attack Compromised 80,000+ Devices, SonicWall Patches 4 SMA1000 Flaws  CVSS 10

Contract and server dispute brought down Bangladesh’s digital payment

Bangladesh's digital payments system remains severely disrupted after a technology conflict forces core card and interbank services offline for millions...
Read More
Contract and server dispute brought down Bangladesh’s digital payment

Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Atlassian has fixed CVE-2026-21589, a serious flaw in Atlassian Data Center with a score of 9.3. This bug allows an...
Read More
Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

FortiBleed is not described as a single newly disclosed Fortinet vulnerability. Instead, attackers reportedly abuse reused, leaked, or weak credentials to access FortiGate appliances.

FortiBleed Campaign Exploits

The exposed infrastructure reportedly showed an organized access-broker operation that scanned for publicly reachable FortiGate SSL VPN portals, tested stolen passwords, cracked password hashes, and verified accounts before selling working access to other cybercriminals.

The attackers allegedly used credential stuffing and password spraying to test credentials obtained from previous data leaks and infostealer logs.

FortiBleed MITRE ATT&CK Techniques :

Tactic Technique MITRE ID
Reconnaissance Active Scanning T1595
Initial Access Exploit Public-Facing Application T1190
Credential Access Password Spraying T1110.003
Credential Access Credential Stuffing T1110.004
Credential Access Credential Dumping T1003
Credential Access Password Cracking T1110.002
Persistence Create Local Account T1136.001
Defense Evasion / Initial Access Valid Accounts T1078
Discovery Account Discovery T1087
Exfiltration Exfiltration Over C2 Channel T1041
Impact Account Access Removal T1531

Organizations need to quickly check all Fortinet admin and VPN accounts, especially any unknown ones like forticloud-sync, fgtsecure, forti_support2, or Technical_support.

Security teams need to check for unusual REST API keys, changes in settings, strange login activity, and links to known bad systems mentioned in the advisory.

SonicWall

SonicWall has fixed four security flaws in its Secure Mobile Access (SMA) 1000 Series devices, including a serious server-side request forgery (SSRF) issue with the highest CVSS score of 10.0.

The company shared security advice SNWLID-2026-0017 on October 6, 2026. SonicWall announced that there is no proof that these four weaknesses are being used by attackers. Still, it urges affected customers to update to the corrected software. The updates apply to both physical and virtual SMA 6210, SMA 7210, and SMA 8200v devices.

Critical Pre-Authentication SSRF

The main issue, known as CVE-2026-102255, impacts the SMA1000 Appliance WorkPlace interface. It comes from an unplanned alternate access point that lets the device work as a forward proxy.

Additional Security Flaws

CVE-2026-102256 is a post-authentication command-injection vulnerability rated 7.8. Under specific conditions, an authenticated administrator could execute arbitrary operating-system commands, resulting in remote code execution. The advisory does not establish that this flaw can be chained with the critical SSRF issue.

CVE-2026-102257, rated 7.2, is a Zip Slip vulnerability in the Appliance Management Console (AMC). A specially crafted archive could cause files to be extracted outside the intended destination folder. SonicWall says this path-traversal issue can lead to remote code execution.

Affected Versions And Required Updates

Affected versions are 12.4.3-03526 and older, and 12.5.0-02952 and older. Customers should upgrade to platform-hotfix 12.4.3-03670 or newer, or 12.5.0-03082 or newer, based on their software branch. SonicWall offers the latest hotfix through MySonicWall and has no workaround for these problems. The latest fixes solve all four issues in both affected firmware versions.

SSL-VPN services on SonicWall firewalls and the SMA 100 Series are safe. This helps admins find the right devices without thinking all SonicWall VPN setups are at risk from this notice.

Check Also

Zimbra mail servers

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. …