Threat Signal

The Threat Signal created by the FortiGuard Labs is intended to provide you with insight on emerging issues that are trending within the cyber threat landscape. The Threat Signal will provide concise technical details about the issue, mitigation recommendations and a perspective from the FortiGuard Labs team in an FAQ style format.

Whether it’s significant vulnerability disclosures including high profile zero days, coordinated announcements with Cyber Threat Alliance partners, malware of significance, or any threat making the news cycle, FortiGuard Threat Signals are there for you.

Update March 1: Added new detections for publicly available IsaacWiper and HermeticWiper samples from ESET blog .UPDATE F...

Feb 23, 2022 TLP Level: Threat Level: MED ID: 9
UPDATE February 17: Added reference to CVE-2022-24087, which Adobe disclosed and issues an out-of-band patch for on Februa...

Feb 15, 2022 TLP Level: Threat Level: MED ID: 8
FortiGuard Labs is aware of various campaigns targeting Ukraine by threat actors known as ACTINIUM/Gamaredon/DEV-0157. ACT...

Feb 04, 2022 TLP Level: Threat Level: MED ID: 7
FortiGuard Labs is aware that a new ransomware called "Sugar" is in the wild. Reportedly, Sugar ransomware targets consume...

Feb 03, 2022 TLP Level: Threat Level: MED ID: 6
FortiGuard Labs is aware that a Proof-of-Concept (POC) code for a newly patched Windows vulnerability (CVE-2022-21882) tha...

Jan 30, 2022 TLP Level: Threat Level: MED ID: 5
FortiGuard Labs is aware of a report that source code of BotenaGo malware was recently made available on GitHub. BotenaGo ...

Jan 27, 2022 TLP Level: Threat Level: MED ID: 4
UPDATE January 19: Updated Coverage section about the third malware that FortiGuard Labs has confirmed as a wiper malware....

Jan 17, 2022 TLP Level: Threat Level: MED ID: 3
UPDATE January 13 2022: Protection section has been updated with a IPS signature information.FortiGuard Labs is aware that...

Jan 12, 2022 TLP Level: Threat Level: MED ID: 2
Update 1/11 - "What is the Status of Coverage" section updatedFortiGuard Labs is aware of newly discovered vulnerability i...

Jan 06, 2022 TLP Level: Threat Level: MED ID: 1
NOTE: 12/30 IPS signature information added FortiGuard Labs is aware of a newly disclosed remote code execution vulnerabil...

Dec 28, 2021 TLP Level: Threat Level: MED ID: 85
FortiGuard Labs is aware of a recently reported ransomware "Rook". According to a publicly available report, Rook appears ...

Dec 27, 2021 TLP Level: Threat Level: MED ID: 84
Mortar Loader is a new process hollowing tool that can be leveraged by threat actors. Process Hollowing is a well-known e...

Dec 26, 2021 TLP Level: Threat Level: MED ID: 83
FortiGuard Labs is aware that the Apache Software Foundation released Log4j version 2.17.0 on December 18th 2021 in respon...

Dec 20, 2021 TLP Level: Threat Level: MED ID: 82
FortiGuard Labs is aware of a new Mirai Linux variant that spreads using CVE-2021-44228 (Log4Shell). This is possibly the ...

Dec 20, 2021 TLP Level: Threat Level: HIGH ID: 83
UPDATE December 17 2021: The Apache Software Foundation has changed Denial of Service to Remote Code Execution and has u...

Dec 15, 2021 TLP Level: Threat Level: MED ID: 81