Fortiguard Labs

Latest Reports

signalreport-logo Threat Signal Report

Multiple ZTNA Products Authentication Bypass
Aug 14, 2025

A series of critical vulnerabilities affecting leading zero trust platforms - Zscaler, Netskope, and Check Point (Perimeter 81) - have been disclosed following a seven-month research campaign by...

fortiguardblog-logo Threat Research Blog

From ClickFix to Command: A Full PowerShell Attack Chain
Aug 11, 2025

A regionally targeted PowerShell-based campaign used phishing lures, obfuscation, and RAT delivery to infiltrate Israeli organizations. Learn how the attack chain worked—and how Fortinet blocked it.      

fortiguardblog-logo Threat Research Blog

Unveiling a New Variant of the DarkCloud Campaign
Aug 07, 2025

FortiGuard Labs has uncovered a stealthy new variant of DarkCloud malware that leverages phishing emails, obfuscated JavaScript, PowerShell loaders, and process hollowing to exfiltrate...

outbreakalert-logo Outbreak Alert

Citrix Bleed 2
Aug 06, 2025

FortiGuard Labs has observed a sharp increase in exploitation attempts targeting the 'Citrix Bleed 2' vulnerability since July 28, 2025. Telemetry indicates activity has surged to over 6,000...

fortiguardblog-logo Threat Research Blog

Malicious Packages Across Open-Source Registries: Detection Statistics and Trends (Q2 2025)
Aug 04, 2025

Malware threats continue to infiltrate open-source software registries. FortiGuard Labs’ Q2 2025 analysis reveals persistent tactics used in malicious NPM and PyPI packages, including credential...

outbreakalert-logo Outbreak Alert

Microsoft SharePoint Zero-day Attack
Jul 31, 2025

FortiGuard Labs has detected and successfully blocked hundreds of exploitation attempts targeting a newly discovered zero-day vulnerability chain in on-premises Microsoft SharePoint servers. This...

fortiguardblog-logo Threat Research Blog

In-Depth Analysis of an Obfuscated Web Shell Script
Jul 25, 2025

Detailed analysis of an obfuscated web shell used in a CNI attack. Explores its structure, traffic patterns, and Fortinet’s detection and protection.      

fortiguardblog-logo Threat Research Blog

Inside The ToolShell Campaign
Jul 25, 2025

FortiGuard Labs uncovers ToolShell, a sophisticated exploit chain targeting Microsoft SharePoint servers using a mix of patched and zero-day CVEs. Learn how attackers deploy GhostWebShell and...

fortiguardblog-logo Threat Research Blog

A Special Mission to Nowhere
Jul 23, 2025

Following the Israel-Iran ceasefire, FortiGuard Labs uncovered a phishing campaign posing as a private jet evacuation service from Tel Aviv to New York. Learn how attackers used crisis-driven fear...

fortiguardblog-logo Threat Research Blog

NailaoLocker Ransomware’s “Cheese”
Jul 18, 2025

FortiGuard Labs analyzes NailaoLocker ransomware, a unique variant using SM2 encryption and a built-in decryption function. Learn how it works, why it matters, and how Fortinet protects against it.      

outbreakalert-logo Outbreak Alert

SonicWall Secure Mobile Access Attack
Jul 18, 2025

A campaign targeting SonicWall SMA 100 series appliances is currently under active exploitation, leveraging both known vulnerabilities and potential zero-days to gain persistent access to...

fortiguardblog-logo Threat Research Blog

Improving Cloud Intrusion Detection and Triage with FortiCNAPP Composite Alerts
Jul 17, 2025

FortiCNAPP Composite Alerts link weak signals into clear timelines—helping security teams detect cloud-native threats earlier and triage them faster.      

fortiguardblog-logo Threat Research Blog

Old Miner, New Tricks
Jul 16, 2025

FortiCNAPP Labs uncovers Lcrypt0rx, a likely AI-generated ransomware variant used in updated H2Miner campaigns targeting cloud resources for Monero mining.      

signalreport-logo Threat Signal Report

Wing FTP Remote Code Execution Vulnerability
Jul 15, 2025

CVE-2025-47812 is a recently disclosed Remote Code Execution (RCE) vulnerability impacting Wing FTP Server, a cross-platform file transfer solution. This critical flaw affects versions prior to...

fortiguardblog-logo Threat Research Blog

How FortiSandbox 5.0 Detects Dark 101 Ransomware Despite Evasion Techniques
Jul 14, 2025

Discover how FortiSandbox 5.0 detects Dark 101 ransomware, even with sandbox evasion tactics. Learn how advanced behavioral analysis blocks file encryption, system tampering, and ransom note...

signalreport-logo Threat Signal Report

Next.js Middleware Auth.Bypass Vulnerability
Jul 11, 2025

FortiGuard Labs has identified ongoing attack attempts targeting a critical authorization bypass vulnerability (CVE-2025-29927) in the middleware system of the Next.js framework, a popular...

outbreakalert-logo Outbreak Alert

Langflow Unauth RCE Attack
Jun 25, 2025

FortiGuard Labs has observed a significant uptick in attacks targeting Langflow, leveraging a recently discovered authentication bypass vulnerability that allows unauthenticated remote attackers...

signalreport-logo Threat Signal Report

Teleport Remote Authentication Bypass
Jun 20, 2025

Teleport security engineers have discovered a critical vulnerability affecting Teleport versions earlier than 17.5.2. This flaw allows remote attackers to bypass SSH authentication on servers...

signalreport-logo Threat Signal Report

Multiple ZTNA Products Authentication Bypass
Aug 14, 2025

A series of critical vulnerabilities affecting leading zero trust platforms - Zscaler, Netskope, and Check Point (Perimeter 81) - have been disclosed following a seven-month research campaign by...

fortiguardblog-logo Threat Research Blog

From ClickFix to Command: A Full PowerShell Attack Chain
Aug 11, 2025

A regionally targeted PowerShell-based campaign used phishing lures, obfuscation, and RAT delivery to infiltrate Israeli organizations. Learn how the attack chain worked—and how Fortinet blocked it.      

fortiguardblog-logo Threat Research Blog

Unveiling a New Variant of the DarkCloud Campaign
Aug 07, 2025

FortiGuard Labs has uncovered a stealthy new variant of DarkCloud malware that leverages phishing emails, obfuscated JavaScript, PowerShell loaders, and process hollowing to exfiltrate...

outbreakalert-logo Outbreak Alert

Citrix Bleed 2
Aug 06, 2025

FortiGuard Labs has observed a sharp increase in exploitation attempts targeting the 'Citrix Bleed 2' vulnerability since July 28, 2025. Telemetry indicates activity has surged to over 6,000...

fortiguardblog-logo Threat Research Blog

Malicious Packages Across Open-Source Registries: Detection Statistics and Trends (Q2 2025)
Aug 04, 2025

Malware threats continue to infiltrate open-source software registries. FortiGuard Labs’ Q2 2025 analysis reveals persistent tactics used in malicious NPM and PyPI packages, including credential...

outbreakalert-logo Outbreak Alert

Microsoft SharePoint Zero-day Attack
Jul 31, 2025

FortiGuard Labs has detected and successfully blocked hundreds of exploitation attempts targeting a newly discovered zero-day vulnerability chain in on-premises Microsoft SharePoint servers. This...

fortiguardblog-logo Threat Research Blog

In-Depth Analysis of an Obfuscated Web Shell Script
Jul 25, 2025

Detailed analysis of an obfuscated web shell used in a CNI attack. Explores its structure, traffic patterns, and Fortinet’s detection and protection.      

fortiguardblog-logo Threat Research Blog

Inside The ToolShell Campaign
Jul 25, 2025

FortiGuard Labs uncovers ToolShell, a sophisticated exploit chain targeting Microsoft SharePoint servers using a mix of patched and zero-day CVEs. Learn how attackers deploy GhostWebShell and...

fortiguardblog-logo Threat Research Blog

A Special Mission to Nowhere
Jul 23, 2025

Following the Israel-Iran ceasefire, FortiGuard Labs uncovered a phishing campaign posing as a private jet evacuation service from Tel Aviv to New York. Learn how attackers used crisis-driven fear...

fortiguardblog-logo Threat Research Blog

NailaoLocker Ransomware’s “Cheese”
Jul 18, 2025

FortiGuard Labs analyzes NailaoLocker ransomware, a unique variant using SM2 encryption and a built-in decryption function. Learn how it works, why it matters, and how Fortinet protects against it.      

outbreakalert-logo Outbreak Alert

SonicWall Secure Mobile Access Attack
Jul 18, 2025

A campaign targeting SonicWall SMA 100 series appliances is currently under active exploitation, leveraging both known vulnerabilities and potential zero-days to gain persistent access to...

fortiguardblog-logo Threat Research Blog

Improving Cloud Intrusion Detection and Triage with FortiCNAPP Composite Alerts
Jul 17, 2025

FortiCNAPP Composite Alerts link weak signals into clear timelines—helping security teams detect cloud-native threats earlier and triage them faster.      

fortiguardblog-logo Threat Research Blog

Old Miner, New Tricks
Jul 16, 2025

FortiCNAPP Labs uncovers Lcrypt0rx, a likely AI-generated ransomware variant used in updated H2Miner campaigns targeting cloud resources for Monero mining.      

signalreport-logo Threat Signal Report

Wing FTP Remote Code Execution Vulnerability
Jul 15, 2025

CVE-2025-47812 is a recently disclosed Remote Code Execution (RCE) vulnerability impacting Wing FTP Server, a cross-platform file transfer solution. This critical flaw affects versions prior to...

fortiguardblog-logo Threat Research Blog

How FortiSandbox 5.0 Detects Dark 101 Ransomware Despite Evasion Techniques
Jul 14, 2025

Discover how FortiSandbox 5.0 detects Dark 101 ransomware, even with sandbox evasion tactics. Learn how advanced behavioral analysis blocks file encryption, system tampering, and ransom note...

signalreport-logo Threat Signal Report

Next.js Middleware Auth.Bypass Vulnerability
Jul 11, 2025

FortiGuard Labs has identified ongoing attack attempts targeting a critical authorization bypass vulnerability (CVE-2025-29927) in the middleware system of the Next.js framework, a popular...

outbreakalert-logo Outbreak Alert

Langflow Unauth RCE Attack
Jun 25, 2025

FortiGuard Labs has observed a significant uptick in attacks targeting Langflow, leveraging a recently discovered authentication bypass vulnerability that allows unauthenticated remote attackers...

signalreport-logo Threat Signal Report

Teleport Remote Authentication Bypass
Jun 20, 2025

Teleport security engineers have discovered a critical vulnerability affecting Teleport versions earlier than 17.5.2. This flaw allows remote attackers to bypass SSH authentication on servers...

signalreport-logo Threat Signal Report

Multiple ZTNA Products Authentication Bypass
Aug 14, 2025

A series of critical vulnerabilities affecting leading zero trust platforms - Zscaler, Netskope, and Check Point (Perimeter 81) - have been disclosed following a seven-month research campaign by...

fortiguardblog-logo Threat Research Blog

From ClickFix to Command: A Full PowerShell Attack Chain
Aug 11, 2025

A regionally targeted PowerShell-based campaign used phishing lures, obfuscation, and RAT delivery to infiltrate Israeli organizations. Learn how the attack chain worked—and how Fortinet blocked it.      

fortiguardblog-logo Threat Research Blog

Unveiling a New Variant of the DarkCloud Campaign
Aug 07, 2025

FortiGuard Labs has uncovered a stealthy new variant of DarkCloud malware that leverages phishing emails, obfuscated JavaScript, PowerShell loaders, and process hollowing to exfiltrate...

outbreakalert-logo Outbreak Alert

Citrix Bleed 2
Aug 06, 2025

FortiGuard Labs has observed a sharp increase in exploitation attempts targeting the 'Citrix Bleed 2' vulnerability since July 28, 2025. Telemetry indicates activity has surged to over 6,000...

fortiguardblog-logo Threat Research Blog

Malicious Packages Across Open-Source Registries: Detection Statistics and Trends (Q2 2025)
Aug 04, 2025

Malware threats continue to infiltrate open-source software registries. FortiGuard Labs’ Q2 2025 analysis reveals persistent tactics used in malicious NPM and PyPI packages, including credential...

outbreakalert-logo Outbreak Alert

Microsoft SharePoint Zero-day Attack
Jul 31, 2025

FortiGuard Labs has detected and successfully blocked hundreds of exploitation attempts targeting a newly discovered zero-day vulnerability chain in on-premises Microsoft SharePoint servers. This...

fortiguardblog-logo Threat Research Blog

In-Depth Analysis of an Obfuscated Web Shell Script
Jul 25, 2025

Detailed analysis of an obfuscated web shell used in a CNI attack. Explores its structure, traffic patterns, and Fortinet’s detection and protection.      

fortiguardblog-logo Threat Research Blog

Inside The ToolShell Campaign
Jul 25, 2025

FortiGuard Labs uncovers ToolShell, a sophisticated exploit chain targeting Microsoft SharePoint servers using a mix of patched and zero-day CVEs. Learn how attackers deploy GhostWebShell and...

fortiguardblog-logo Threat Research Blog

A Special Mission to Nowhere
Jul 23, 2025

Following the Israel-Iran ceasefire, FortiGuard Labs uncovered a phishing campaign posing as a private jet evacuation service from Tel Aviv to New York. Learn how attackers used crisis-driven fear...

fortiguardblog-logo Threat Research Blog

NailaoLocker Ransomware’s “Cheese”
Jul 18, 2025

FortiGuard Labs analyzes NailaoLocker ransomware, a unique variant using SM2 encryption and a built-in decryption function. Learn how it works, why it matters, and how Fortinet protects against it.      

outbreakalert-logo Outbreak Alert

SonicWall Secure Mobile Access Attack
Jul 18, 2025

A campaign targeting SonicWall SMA 100 series appliances is currently under active exploitation, leveraging both known vulnerabilities and potential zero-days to gain persistent access to...

fortiguardblog-logo Threat Research Blog

Improving Cloud Intrusion Detection and Triage with FortiCNAPP Composite Alerts
Jul 17, 2025

FortiCNAPP Composite Alerts link weak signals into clear timelines—helping security teams detect cloud-native threats earlier and triage them faster.      

fortiguardblog-logo Threat Research Blog

Old Miner, New Tricks
Jul 16, 2025

FortiCNAPP Labs uncovers Lcrypt0rx, a likely AI-generated ransomware variant used in updated H2Miner campaigns targeting cloud resources for Monero mining.      

signalreport-logo Threat Signal Report

Wing FTP Remote Code Execution Vulnerability
Jul 15, 2025

CVE-2025-47812 is a recently disclosed Remote Code Execution (RCE) vulnerability impacting Wing FTP Server, a cross-platform file transfer solution. This critical flaw affects versions prior to...

fortiguardblog-logo Threat Research Blog

How FortiSandbox 5.0 Detects Dark 101 Ransomware Despite Evasion Techniques
Jul 14, 2025

Discover how FortiSandbox 5.0 detects Dark 101 ransomware, even with sandbox evasion tactics. Learn how advanced behavioral analysis blocks file encryption, system tampering, and ransom note...

signalreport-logo Threat Signal Report

Next.js Middleware Auth.Bypass Vulnerability
Jul 11, 2025

FortiGuard Labs has identified ongoing attack attempts targeting a critical authorization bypass vulnerability (CVE-2025-29927) in the middleware system of the Next.js framework, a popular...

outbreakalert-logo Outbreak Alert

Langflow Unauth RCE Attack
Jun 25, 2025

FortiGuard Labs has observed a significant uptick in attacks targeting Langflow, leveraging a recently discovered authentication bypass vulnerability that allows unauthenticated remote attackers...

signalreport-logo Threat Signal Report

Teleport Remote Authentication Bypass
Jun 20, 2025

Teleport security engineers have discovered a critical vulnerability affecting Teleport versions earlier than 17.5.2. This flaw allows remote attackers to bypass SSH authentication on servers...

Certifications

  • av comparatives logo
  • common criteria logo
  • nss labs logo
  • vb logo
  • mitre logo