Friday , July 31 2026
FortiWeb

FortiWeb Auth Bypass Vuln Exploited: Script to Detect Vuln Appliances

A Fortinet FortiWeb vulnerability is being exploited to create new admin users on exposed devices without any authentication. The issue is fixed in FortiWeb 8.0.2, and admins are urged to update as soon as possible and check for signs of unauthorized access.

Source: Defused

Threat intelligence firm Defused discovered an “Unknown Fortinet exploit” targeting exposed devices to create admin accounts on October 6.

EDIC Propose to invest $2 billion in an AI data center in Bangladesh

Many groups from different countries want to build AI data centers in Bangladesh. Countries like the UK, Japan, and South...
Read More
EDIC Propose to invest $2 billion in an AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

According to new research published by Daniel Card of PwnDefend and Defused, the flaw is a path traversal issue affecting the following Fortinet endpoint: (/api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi)

Threat actors are sending HTTP POST requests to this path containing payloads that create local admin-level accounts on the targeted device.

Researchers found multiple sets of usernames and passwords like Testpoint, trader1, and trader, with passwords including 3eMIXX43, AFT3$tH4ck, and AFT3$tH4ckmet0d4yaga!n.

The attacks originated from a wide range of IP addresses, including:

107.152.41.19
144.31.1.63
Addresses in the 185.192.70.0/24 range
64.95.13.8 (from original October report)

Security researchers at watchTowr Labs have verified the exploit, sharing a video on X that shows a failed FortiWeb login attempt, the exploit execution, and the successful login as the new admin user.

watchTowr also released a tool called “FortiWeb Authentication Bypass Artifact Generator,” which attempts to exploit the flaw by creating an admin user with an 8-character random username derived from a UUID.

The tool was released to help defenders identify vulnerable devices.

Rapid7 reports that the flaw impacts FortiWeb versions 8.0.1 and earlier. It was resolved in version 8.0.2, released at the end of October.

BleepingComputer reported an inability to find any disclosure of a FortiWeb vulnerability on Fortinet’s PSIRT site that matches the one being exploited.

WatchTowr Labs’ open-source tool, hosted on GitHub at watchTowr-vs-Fortiweb-AuthBypass, simplifies detection by simulating the bypass mechanism. The Python script generates a unique username and password (e.g., “35f36895”) and sends an exploit payload to the target IP, such as python watchTowr-vs-Fortiweb-AuthBypass.py 192.168.1.99.

Source: Defused, pwndefend, Daniel_Card, BleepingComputer

Check Also

5

TP-Link alerts users to patch router auth bypass vulnerability

TP-Link fixed some security flaws in its Archer NX routers. CVE-2025-15517 is a security flaw …