Security News

The latest security stories, summarized by AI

More Security Stories

Fortinet SSL VPN and FortiGate vulnerabilities under active attack

Originally Published 18 days ago — by The Hacker News

Featured image for Fortinet SSL VPN and FortiGate vulnerabilities under active attack
Source: The Hacker News

Fortinet has issued a warning about active exploitation of a five-year-old vulnerability in FortiOS SSL VPN (CVE-2020-12812) that allows attackers to bypass two-factor authentication under certain configurations, especially involving LDAP integration and case-sensitive username matching. Organizations are advised to update their systems or disable username sensitivity to mitigate the risk, and to contact support if they suspect exploitation.

Fake MAS Domain Distributes PowerShell Malware

Originally Published 18 days ago — by BleepingComputer

Featured image for Fake MAS Domain Distributes PowerShell Malware
Source: BleepingComputer

A malicious domain mimicking Microsoft's MAS tool was used to spread Cosmali Loader malware via PowerShell, exploiting user typos to infect Windows systems with cryptomining and RAT malware. Users are advised to verify commands and avoid executing untrusted remote code to prevent infection.