What the CDSL Malware Attack Teaches Organizations About VAPT?
Most organizations believe that completing an annual Vulnerability Assessment and Penetration Testing...
Read more ›Fortinet issues a warning on a new Zero-Day attack on Fortinet FortiGate firewall devices with management interfaces exposed to the public. The campaign began around mid-November 2024 by accessing management interfaces, creating new admin accounts, changing configurations, and bypassing SSL VPN for lateral movement. The threat actors are unknown, and they have taken advantage of this vulnerability to extract credentials using DCSync.
For context, a Zero-Day is an unknown software vulnerability exploited by hackers to gain entry into vulnerable networks, servers, and systems. It is called Zero-Day because it occurs before an organization becomes aware of it, giving them zero days to address the issue.
The firmware devices that were impacted and are still undergoing recovery range between 7.0.14 and 7.0.16, which were released in February and October of 2024.
Also Read: A Critical Vulnerability Rating 10/10 Has Been Confirmed By Microsoft
Fortinet has confirmed that the attacks came in four waves:
Currently, Fortinet has given its response to update its firmware and minimize public-facing interfaces to control future threats.
Simply put, a fault in a firewall was used to gain bigger access, create an entryway for hackers, and move deeper into their networks. As a SOC service provider, we’d agree no security is too much security. If you harbor confidential data that can put an entire organization or a chain of clients at risk, then having 24/7 SOC monitoring can save you potentially costly losses and lawsuits.
Most organizations believe that completing an annual Vulnerability Assessment and Penetration Testing...
Read more ›
In a world where cyber threats evolve faster than ever, Managed Service...
Read more ›
In today’s evolving cybersecurity landscape, Managed Service Providers (MSPs) face increasing pressure...
Read more ›Most breaches begin with a gap no one was watching. Tell us what you're protecting and our SOC analysts will pressure-test your defenses and show you exactly where you stand.
Phone
+1 607 360 5504
Sales Office - United States
651, N Broad St, Middletown
Delaware-19709
Operations Center- India
Level 17, TransAsia Cyber Park
Kochi, Kerala-682030
Data privacy notice.
All submissions are protected via TLS 1.3 encryption in transit and
processed within our secure, air-gapped data environment. We never resell your data.