Tuesday , September 29 2026
FortiGate

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access trojan (RAT). This makes the affected devices key points for spying and stealing information.

The SOCRadar Threat Research Unit has found that attackers are using CVE-2025-25249. This is a serious flaw in the cw_acd daemon in FortiOS and FortiSwitchManager.

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Rated 9.8 on the CVSSv3 scale, this weakness lets attackers from afar run any code they want by sending special requests to the CAPWAP Control service, which is found on UDP port 5246.

Fortinet uses CAPWAP to control wireless access points from one place. This makes the system available on many FortiGate devices that connect to the internet. The affected versions include FortiOS 6.4 to 7.6.3 and FortiSwitchManager 7.0.x and 7.2.x, but Fortinet released fixes after the news was shared on January 13, 2026.

Administrators should limit outside access to CAPWAP Control ports, look for strange Node.js processes and files like /tmp/.i.js on open devices, and review active sessions for links to known bad IP addresses.

Because PivotC2 collects device settings in bulk, any group that sees hints of a breach should consider all saved passwords, like SSL-VPN, LDAP, and IPSec keys, to be unsafe and change them right away.

FortiSandbox Vulnerability

Fortinet has revealed a serious vulnerability in its FortiSandbox platform. It warn that attackers without permission could take advantage of issues in the web interface to steal sensitive information without needing valid logins.

The flaw, tracked as CVE-2026-26084, stems from improper access control in the graphical user interface component that FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS all share, and it has been assigned a CVSS v3.1 score of 8.9, placing it firmly in the high-severity category.

FortiOS and FortiProxy ZTNA Validation Vulnerabilit:

Fortinet has revealed a serious flaw with certificate validation in the Agentless ZTNA portal of FortiOS and FortiProxy. This issue could allow an unauthorized remote attacker to intercept traffic between the ZTNA portal and the website it connects to.

Tracked as CVE-2026-84393 and noted in advisory FG-IR-26-174, the flaw was released on September 8, 2026, and has a CVSSv3 score of 7.3. The weakness comes from a flawed certificate check, classified as CWE-295, in the Agentless ZTNA portal part. Zero Trust Network Access portals aim to create safe connections with identity checks between users and internal apps without needing a complete VPN client.

Check Also

Secure Email Gateway

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known …