In late November and December 2024, Arctic Wolf observed evidence of a mass compromise of Fortinet FortiGate. While the initial attack vector was unknown at the time, evidence of compromise (with new users and SSL profiles) was consistent across compromised devices.
CVE-2024-55591: Fortinet FortiOS/FortiProxy Zero Day
Recent Posts
- CVE-2024-13434 – “WordPress WP Inventory Manager Reflected Cross-Site Scripting Vulnerability”
- CVE-2024-13401 – “PayPal WordPress Stored Cross-Site Scripting Vulnerability”
- CVE-2024-13398 – PayPal Checkout for WordPress Stored Cross-Site Scripting
- CVE-2024-51462 – IBM QRadar WinCollect Agent XML Injection Vulnerability
- CVE-2024-52363 – IBM InfoSphere Information Server Directory Traversal Vulnerability