Fortinet has acquired Virtue AI to enhance its security offerings related to artificial intelligence. This move is part of Fortinet's strategy to address the expanding security needs as organizations increasingly deploy AI applications and autonomous agents. With this acquisition, Fortinet aims to protect against new vulnerabilities that arise from these technologies, which now include various AI components such as prompts, models, and APIs. As businesses adopt AI, their security measures must evolve to cover not just traditional IT infrastructure but also the unique risks associated with AI systems. This acquisition signifies Fortinet's commitment to staying ahead in the rapidly changing cybersecurity landscape.
Fortinet has addressed serious authentication vulnerabilities in its FortiWeb and FortiManager products that could potentially allow attackers to log in using arbitrary usernames and passwords. Additionally, these flaws could enable an attacker to impersonate any FortiGate appliance, raising significant security concerns for users of these systems. The vulnerabilities impact organizations relying on Fortinet's web application firewall and management tools, which are commonly used to protect sensitive data and infrastructure. Companies using these products should prioritize applying the latest patches to mitigate any risk of unauthorized access. The situation serves as a reminder of the importance of regular updates and monitoring security advisories from vendors.
Siemens has alerted users to vulnerabilities affecting its RUGGEDCOM APE1808 device due to issues in Fortinet's FortiOS software. Two specific vulnerabilities, identified as CVE-2026-23573 and CVE-2026-59839, can allow attackers to execute unauthorized commands or access restricted files if they have the necessary privileges. These vulnerabilities could potentially impact critical sectors such as manufacturing, energy, and transportation. Siemens advises affected users to contact their customer support for more details on mitigation measures and to follow Fortinet's advisory for workarounds. This situation underscores the need for robust network security measures to safeguard critical infrastructure.
Hackers recently targeted a combined heat and power (CHP) plant in Poland, exploiting vulnerabilities in a Fortinet device and a private Access Point Name (APN). This breach allowed attackers to access key components like Programmable Logic Controllers (PLCs), leading to disruptions in turbine operations and water treatment systems. The Polish Computer Emergency Response Team (CERT) labeled this incident as a significant threat to the energy sector, particularly because it illustrates how seemingly standard network configurations can provide a pathway for cyberattacks. The implications of this breach are serious, as disruptions in energy infrastructure can have widespread effects on public services and safety.
Cybersecurity researchers have identified a supply chain attack targeting QuickFox, a VPN tool favored by overseas Chinese users. The attack has reportedly been active since at least August 2025, involving a compromised version of the application that delivers the FDMTP backdoor. This backdoor allows attackers to gain unauthorized access to affected systems, posing significant risks to user privacy and data security. This incident raises concerns about the security of software supply chains, particularly for tools that are essential for users in sensitive environments. Users of QuickFox should be vigilant and consider alternative solutions while the situation is investigated further.
On July 27, 2026, federal cybersecurity officials issued an emergency alert regarding serious vulnerabilities found in Fortinet and Arista routers. These flaws are reportedly being exploited by attackers, raising concerns about the security of networks that rely on these devices. Organizations using affected Fortinet and Arista products are urged to implement the necessary patches to protect against potential breaches. This situation underscores the need for timely updates and vigilant monitoring of network devices, as attackers are actively seeking to exploit these weaknesses. Federal authorities are closely monitoring the situation and advising companies to prioritize these updates to safeguard their systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities associated with Arista VeloCloud Orchestrator and Fortinet's FortiOS to its Known Exploited Vulnerabilities catalog. The specific vulnerability for Arista is identified as CVE-2025-68686. This inclusion indicates that these flaws are being actively exploited, posing a significant risk to users of these products. Organizations using Arista's VeloCloud Orchestrator or Fortinet's FortiOS should take immediate action to address these vulnerabilities to safeguard their systems from potential attacks. The urgency of this update emphasizes the need for timely patching and monitoring of network security.
The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that they are actively being exploited by attackers. The first vulnerability, CVE-2025-68686, affects Fortinet's FortiOS, allowing unauthorized access to sensitive information. The second, CVE-2026-16812, impacts Arista's VeloCloud Orchestrator, enabling command injection attacks on the on-premises operating system. These vulnerabilities pose serious risks, particularly to federal agencies, which are urged to prioritize their remediation under Binding Operational Directive 26-04. While the directive specifically targets federal civilian agencies, CISA recommends that all organizations adopt similar risk-based approaches to vulnerability management to protect against these threats.
A new variant of the TrickBot malware has been identified, which employs DNS tunneling for its command and control operations. Researchers at Fortinet's FortiGuard Labs noted that this version has a modular architecture and has made changes to its transport layer. This adaptation makes it more difficult for traditional security measures to detect and block its communications. TrickBot is known for stealing sensitive information and facilitating other cyberattacks, which raises concerns for organizations that may be targeted. As cyber threats evolve, companies need to stay vigilant and enhance their defenses against such sophisticated attacks.
The Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities Catalog due to evidence that they are being actively exploited. The vulnerabilities include two related to Fortinet's FortiSandbox, identified as CVE-2026-25089 and CVE-2026-39808, both of which are OS command injection flaws. The third vulnerability, CVE-2026-58644, affects Microsoft SharePoint and involves the deserialization of untrusted data. These vulnerabilities present serious risks, especially to federal agencies, which are urged to prioritize their remediation as mandated by CISA’s Binding Operational Directive 26-04. While this directive applies specifically to federal civilian agencies, CISA encourages all organizations to adopt similar practices for managing vulnerabilities. Organizations are also invited to report any exploited vulnerabilities not currently listed in the KEV Catalog.
Fortinet, Ivanti, and ServiceNow have all issued important patches for various vulnerabilities in their products. A notable issue was found in the ServiceNow AI platform, where a critical security flaw could allow remote attackers to execute arbitrary code. This vulnerability poses a significant risk to users, as it could enable unauthorized access and control over affected systems. Organizations using the ServiceNow platform should act quickly to apply the available updates to protect against potential exploitation. The situation serves as a reminder for companies to regularly update their software to mitigate risks from such vulnerabilities.
The FortiBleed credential theft campaign has been tied to the operations of the INC group and Lynx ransomware, indicating that attackers are using stolen Fortinet credentials for future network attacks. This campaign has raised concerns among organizations that rely on Fortinet products, as it could lead to further intrusions into their networks. The stolen credentials can enable cybercriminals to bypass security measures, making it easier for them to deploy ransomware or steal sensitive data. Companies must be vigilant and review their security practices to mitigate the risk posed by these ongoing attacks. This incident serves as a reminder of the importance of securing credentials and monitoring for suspicious activity.
In a recent discussion, cybersecurity expert Sandy Bird addressed the challenges of maintaining cloud visibility and the risks associated with vulnerabilities like FortiBleed. This specific flaw affects Fortinet's FortiOS and FortiProxy, which are widely used in enterprise environments. If exploited, it can allow attackers to gain unauthorized access to sensitive data. The conversation also touched on how many security incidents occur due to simple oversights, emphasizing the need for better monitoring and security practices. As more organizations move their operations to the cloud, understanding these vulnerabilities is crucial for safeguarding against potential breaches.
A Russian initial access broker has been linked to the FortiBleed campaign, employing a custom sniffer to capture more than 110 million user credentials since at least February 2026. This campaign raises significant concerns as it highlights the scale at which attackers are operating and the potential dangers to various organizations that may be compromised by these stolen credentials. The threat actor's methods indicate a sophisticated approach to infiltrating networks, which could lead to further exploitation or data breaches. Organizations need to be vigilant and enhance their security measures to protect against such attacks, particularly as the stolen credentials could be used in various malicious activities. The implications of this breach extend beyond immediate threats, as it underscores the ongoing risk posed by credential theft in the cybersecurity landscape.
Fortinet has acknowledged a serious credential-harvesting campaign known as FortiBleed, which has resulted in the collection of over 86,000 confirmed working credentials. This campaign poses a significant risk to users and organizations that utilize Fortinet's products, as attackers can exploit these credentials for unauthorized access to sensitive systems. The incident is particularly alarming because it affects a wide range of users, potentially including businesses that rely on Fortinet's security solutions. Companies should take immediate steps to secure their systems and monitor for any suspicious activities, as the implications of this data breach could lead to further attacks or data leaks. This situation underscores the ongoing challenges in cybersecurity and the need for constant vigilance.