"Fortinet's Critical Flaws: Urgent Patching Needed Amid Ongoing Exploitation"

TL;DR Summary
Fortinet faced a tumultuous week with the disclosure of critical security vulnerabilities in its FortiOS, including an SSL VPN flaw that allows for remote code execution. The company also faced backlash for a confusing double bug disclosure and a disputed claim about toothbrushes being used in a DDoS attack. Fortinet's delayed and conflicting responses to these issues have drawn criticism, while security researchers urge users to patch vulnerable VPNs and upgrade to fixed releases.
- Fortinet's week to forget: Critical vulns, disclosure screw-ups, and that toothbrush DDoS attack claim The Register
- New Fortinet RCE flaw in SSL VPN likely exploited in attacks BleepingComputer
- Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation The Hacker News
- Fortinet urges patching N-day bug amid ongoing nation-state exploitation CSO Online
- Double trouble replay for Fortinet as it reissues critical FortiSIEM vulns The Register
Reading Insights
Total Reads
0
Unique Readers
2
Time Saved
5 min
vs 6 min read
Condensed
93%
1,102 → 74 words
Want the full story? Read the original article
Read on The Register