Mark a Best Answer
Fortinet Community
Recently active
Overview One of Fortinet customers, a large fintech organization, leverages TeamCity to deploy auto-scaling EC2 workload in their AWS environment. The customer builds new resources by automatically starting and stopping cloud-hosted agents on-demand, depending on the current build queue workload. They also use FortiCNAPP (Lacework) to protect their cloud native applications and resources. During periodic scan, FortiCNAPP discovered 10% of the EC2 workload from certain AMI images expose to CVE-2023-42793 which has the score of 9.8 where attackers had already deployed the publicly available exploit without authentication supporting remote code execution on the victim server using a basic web request to any accessible web server hosting the vulnerable application. Incident Summary Attack Vector: CVE exploitation on AWS workloads Impact: Remote code execution for unauthenticated users, enabling access to critical applications running on EC2 Initial Entry Point: Application accessed
Overview One large cooperative bank is tackling modern cloud security challenges head-on through a comprehensive digital transformation, migrating workloads from on-premises data centers to AWS. The bank is reinventing its digital and customer experiences through innovative new services, while enabling its remote workforce to securely and efficiently access private applications. During this transition, the bank experienced a security incident involving a Server-Side Request Forgery (SSRF) attack in its AWS environment. The breach highlighted the risks of cloud-native architectures when combined with misconfigurations and legacy service settings. To contain the incident and strengthen their security posture, the bank engaged the Fortinet Incident Response (IR) Team, which conducted a full investigation using the Fortinet FortiCNAPP platform and delivered a comprehensive cloud security remediation plan. Incident Summary Attack Vector: SSRF vulnerability in a
Exciting updates available on the FortiSOAR Content Hub!! The Fortinet FortiManager ZTP Flow integration brings FortiManager's central management solution to Fortinet's security appliances such as firewalls and VPNs, seamlessly incorporating the Zero-Touch Provisioning (ZTP) flow. This allows for automated device configuration and deployment, reducing the need for manual intervention and enabling quick, plug-and-play setup. Additionally, the Outbreak Response - Apache Tomcat RCE solution pack works in tandem with the Threat Hunt rules in the Outbreak Response Framework to identify and investigate potential Indicators of Compromise (IOCs) associated with the Apache Tomcat remote code execution vulnerability, CVE-2025-24813. This vulnerability is actively targeted by attackers, and the solution aids in detecting and mitigating threats within operational environments such as FortiSIEM and FortiAnalyzer. Our Cisco ISE integration with FortiSOAR™ enhances network policy
Author: @kcheung DNS: Overview & Threats DNS (Domain Name System) is integral to enterprise IT infrastructure, providing services for name resolution. Without DNS, an IT infrastructure is unable to look up a domain’s IP address. Since DNS is available in many IT infrastructures, its role makes it a target for malicious activity. Enterprises must adopt layered defenses and monitor DNS activity to mitigate threats effectively. DNS C2 commands can appear like normal DNS requests and thus make DNS based threats difficult to detect. Enterprise with firewalls that typically allow DNS traffic (port 53), hence use of a multi layered detection and response systems (Ex: EDR, NDR) is crucial in identifying threats. FortiNDR Cloud offers multiple levels of network-based DNS threats detections and response. This blog will go deeper into how you can leverage them to understand, respond and mitigate any such threats and secure your organization’s network. DN
We are pleased to announce the latest updates to the FortiSOAR platform, bringing enhanced capabilities and new integrations designed to further empower your security operations. This release introduces several new Solution Packs and Connector updates that will enhance your ability to manage and respond to various security threats more effectively. Among the updates, we have introduced Solution Packs such as the FortiManager ZTP Flow, multiple Outbreak Response packs covering critical vulnerabilities and attacks, as well as an upgrade to the Threat Intel Management pack. These additions are designed to address emerging threats and streamline incident response workflows. In addition, several Connector updates are now available, including enhancements to platforms such as Exchange, Fortinet FortiAppSec Cloud, Google Gemini, and Mandiant Threat Intelligence, among others. These updates offer improved integration, expanded coverage, and more reliable data sources for your sec
What is CVE-2014-100005? CVE-2014-100005 is a critical vulnerability identified in older D-Link DIR-600 routers. This Cross-Site Request Forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of administrators. By crafting malicious requests, attackers can alter router settings without the administrator’s knowledge, potentially leading to unauthorized account creation or remote management activation. The vulnerability is specifically noted in firmware versions before 2.17b02. How the Vulnerability Works: In the case of D-Link DIR-600 routers, the CSRF vulnerability allows an attacker to send a specially crafted HTTP request to the router's administrative interface, effectively causing the router to perform actions that would normally require administrator-level access. This could include: Changing router settings: For example, modifying network configurations or security settings. Creating unauthorized accounts:
What is CVE-2022-37055? CVE-2022-37055 is a critical buffer overflow vulnerability in D-Link Go-RT-AC750 models GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02. It allows remote code execution due to insufficient buffer size checks in the device's web interface, affecting the CGI and HNAP main components. The Significance of CVE-2022-37055 Buffer overflow vulnerabilities like CVE-2022-37055 are particularly severe because they enable attackers to overwrite memory beyond its allocated limits, potentially injecting and executing malicious code on the affected device. This can grant unauthorized control to attackers, allowing them to manipulate device settings, intercept sensitive data, or use the compromised device as a foothold for further attacks. Additionally, such vulnerabilities can lead to data leakage, service disruptions, or even complete system failure, posing significant threats to network security and data integrity. If exploited, attackers could
What is CVE-2024-1708? CVE-2024-1708 is a critical path traversal vulnerability impacting ConnectWise ScreenConnect versions up to 23.9.7. This flaw enables attackers to manipulate file paths, potentially gaining unauthorized access to files or directories located outside the intended restricted directory. Exploitation of this vulnerability could lead to remote code execution or compromise sensitive data and critical systems. The Importance of CVE-2024-1708 Path traversal vulnerabilities pose a significant threat because they allow attackers to navigate beyond the intended directory restrictions within web applications. By exploiting these vulnerabilities, attackers can access sensitive system files that are typically inaccessible through normal application usage. This could result in the disclosure of confidential information, compromise of system integrity, or facilitate subsequent attacks targeting other areas within the network infrastructure. Such exploits
Secure Connectivity for Mobile Fleets: FortiExtender Vehicle 211F By @PatVita | Director of Product Marketing, FortiExtender If you’re a close follower of Fortinet product news, chances are you’ve heard rumors of a mobility solution coming to the FortiExtender family. I’m happy to say the wait is over: FortiExtender Vehicle is here. Secure Connectivity for Mobile Fleets Many IT teams struggle to service mobile fleets. Whether it’s a public safety, transportation, logistics, or the travel industry fleet, vehicles are unique in that they require secure connectivity to cloud applications but cannot leverage wired broadband. Adding point solutions creates complexity and risk for organizations. Mobile fleets cannot become another silo for enterprise IT. Secure connectivity for must be delivered within a digital platform alongside other areas of IT, such as OT, IoT and wireless access, Enter FortiExtender Vehicle 211F
FortiSOAR Community Update: Powering Up with Industry Favorites! This month's spotlight is on the tools and solutions that have become indispensable to SOC teams across industries. From tackling outbreaks with precision to enhancing system monitoring, these updates are here to streamline your workflows and boost your security posture. Our Outbreak Response Framework together with its Configuration Wizard remain industry champions, offering swift and efficient responses to emerging threats. Coupled with the Fortinet FortiGuard Outbreak connector, these tools ensure you're always one step ahead of the threat landscape. And for those looking to enhance their data protection strategies, the Fortinet FortiDLP connector is here to secure your sensitive information with ease. The IBM Security QRadar SOAR and Maxmind connectors continue to deliver insights and integrations that empower your team. Add FortiSOAR's own System Monitoring and Netscout's Arbor Edge Defense to the mix, and you
What is CVE-2019-7256? CVE-2019-7256 is a serious command injection vulnerability affecting Linear eMerge E3-Series access control systems. It stems from improper sanitization of user inputs, enabling remote attackers to inject and execute arbitrary commands. The severity of this vulnerability is high due to the potential for unauthorized command execution. Attackers can gain complete control over the eMerge E3-Series systems, allowing them to alter configurations, access sensitive data, or disrupt operations. This poses a significant security risk for organizations that depend on these systems for physical security and access management. This vulnerability highlights the importance of robust input validation and secure coding practices in developing network-connected devices. To mitigate CVE-2019-7256, organizations should promptly apply vendor-supplied patches or updates. Additionally, they should implement network segmentation, access controls, and monitoring to de
FortiWeb Security Insights: Addressing XSS Vulnerability in Serenity Software (CVE-2023-31285) What is CVE-2023-31285? CVE-2023-31285 is a Cross-Site Scripting (XSS) vulnerability discovered in Serenity Serene and StartSharp versions prior to 6.7.0. This issue allows attackers to upload malicious HTML or HTM files through a feature meant for temporary file uploads. The vulnerability is particularly concerning because it enables the execution of harmful scripts in the administrator’s browser. Exploiting this flaw could allow attackers to perform actions on behalf of the administrator or access sensitive information. Why CVE-2023-31285 is a Critical Security Concern XSS vulnerabilities are crucial because they compromise the security and integrity of user interactions on a website. Attackers exploiting these flaws can manipulate web sessions and gain access to confidential information, thereby jeopardizing the overall security of the application.&nbs
Last year we launched a network security solution in the Azure Marketplace that protects both east-west and north-south traffic as it passes through Azure Virtual WAN (vWAN). This security is provided through FortiGate VM, in the form of a managed Network Virtual Appliance (NVA) There are multiple use cases supported with our offering. This includes a secure SD-WAN, SD-WAN with next-generation firewall (NGFW), and solely NGFW with layer 4-7 inspection. The integration of FortiGate VM with Secure SD-WAN and Azure vWAN allows users to more effectively interconnect with applications and workloads running in Azure with the rest of their hybrid and multi-cloud deployments. The result is an even simpler, further automated, and operationally efficient cloud on-ramp and SD-WAN experience and the ability to apply NGFW policies to vWAN traffic. Now, we have released an extension of this offering to include internet-inbound traffic, also known as Destination NAT. We are one o
We're pleased to announce the FortiSOAR 7.6.1 release. This new release provides the following key features: FortiFlex licensing Reduced downtime when upgrading HA clusters from 7.6.1 onwards Support for disk encryption Improved solution pack upgradability to preserve custom playbooks Improved management of playbook logs to optimize storage Various UI/UX enhancements Significant improvements to the Outbreak Response feature Improved indicator extraction Voice dictation into the FortiAI assistant Various integration and connector enhancements ...and more! see the release notes below for full details. Release notes:FortiSOAR 7.6.1 Release Notes (opens in new page) Availability and Upgrade:Customers with valid support contracts can upgrade from FortiSOAR 7.6.0 to version 7.6.1. FortiSOAR 7.6.1 can be downloaded from support.fortinet.com
FortiSOAR 7.6.1 is Here! Your SOC Just Got Smarter and Faster SOC operators, analysts, and cyber warriors—get ready for a big boost! FortiSOAR 7.6.1 has arrived, and it's packing a punch stronger than your morning coffee. Check out what's new: FortiFlex Licensing Support Reduced Downtime for HA Clusters Disk Encryption Support Improved Solution Pack Upgradability Optimized Playbook Log Management UI/UX Enhancements Enhanced Outbreak Response Improved Indicator Extraction Voice Dictation with FortiAI Assistant Integration and Connector Enhancements ...and so much more! Dive into the full details here: Release Notes. Upgrade to FortiSOAR 7.6.1 Already on version 7.6.0? Upgrading is a breeze! Visit support.fortinet.com and navigate to: Downloads > Firmware Images > FortiSOAR > 7.0.0 > 7.6 > 7.6.1 What's Fresh Since Our Last Announcement? The following table summarizes the progress we have made with respect to solutions since the last ann
Modern applications are the backbone of digital transformation but protecting them has become a daunting challenge. Organizations are grappling with the complexity of multi-cloud environments, evolving architectures, agile development practices, and emerging threats. These factors, coupled with a shortage of skilled professionals, expand the attack surface and create significant visibility gaps. The distributed nature of data across these environments further increases the likelihood of misconfigurations, inconsistencies, and human errors, all of which can lead to data breaches, service disruptions, and enforcement challenges. The Growing Complexity of Application Security Multi-Cloud Environments: Enterprises now operate across multiple cloud providers, each with unique security controls and configurations. This diversity can lead to inconsistencies and potential vulnerabilities. Evolving Architectures: The adoption of microservices, containerization, and serverless com
Introduction: Streamlining Software Deployment with AWS Marketplace Image Builder AWS Marketplace has introduced an innovative feature to simplify software deployment for customers and sellers alike: the AWS Marketplace EC2 Image Builder. This feature allows customers to discover, purchase, and deploy third-party software directly through the EC2 Image Builder console and Image Builder APIs. With a straightforward console-driven onboarding process, customers can access security tools, OS hardening scripts, and analytics applications to create optimized, secure, and compliant images—referred to as “golden images”—tailored to their needs. Whether you’re a seller looking to expand reach or a customer seeking a streamlined way to integrate third-party applications, this blog post is for you. In the previous blog post, we described what EC2 Image Builder is at a high level, and how it can alleviate the operational overhead of deploying software such as
Looking for a sassy way to secure your distributed workforce? Well, look no further — Fortinet FortiSASE (yes, that's Forti-sassy) has arrived! This cutting-edge connector adds some serious attitude to your cybersecurity arsenal by extending enterprise-grade security to users wherever they are. Whether you're in the office, working remotely, or sipping a latte at your favorite café, FortiSASE has your back (and your network). But that's not all! Here's a quick peek at the latest additions making waves in FortiSOAR: Our Outbreak Response packs are on high alert, tackling critical vulnerabilities like the Palo Alto Networks Management Interface Attack and the Progress Kemp LoadMaster OS Command Injection Vulnerability. Because cyberthreats don't take coffee breaks, and neither do we. CylancePROTECT is stepping up to keep malware at bay with AI-driven endpoint security. It's like having a cybersecurity crystal ball but cooler. Infoblox DDI brings seamless DNS, DHCP, and IPA
FortiSOAR's latest updates are here, and we've added some powerhouse connectors and solution packs that'll make your SOC team look like superheroes—minus the capes (but feel free to wear one if you'd like!). Whether you're facing ransomware threats, digging through cloud analytics, or looking to streamline incident response, our recent releases cover it all. With the Lacework FortiCNAPP, you get unparalleled cloud visibility, empowering you to innovate with confidence. The new Outbreak Response packs keep you ahead of emerging cyber threats like Mallox ransomware and vulnerabilities that dare to show up uninvited. For those of you who live for analytics, we've got Azure Log Analytics and Splunk updates to help you dive deep, uncovering insights faster than ever. And let's not forget our trusty AWS WAF and Akamai WAF connectors that add an extra layer of security to keep the bad guys out (they've had enough practice getting in). Integrations with Google Sheets and M
A prominent US-based specialty engineering and construction company faced challenges centralizing security controls, gaining visibility into traffic patterns and intrusion attempts, and applying policies at the application level within their cloud infrastructure. They turned to Fortinet Cloud Consulting Services to develop a comprehensive cloud network security design tailored to their unique requirements to ensure top-tier security and operational efficiency on AWS. Guided Expertise in Selecting the Right Cloud Architecture The Fortinet Cloud Consulting Services team worked closely with the customer to create an architecture that emphasized scalability, reliability, and robustness. The Fortinet consultants outlined multiple options, highlighting their unique benefits and potential challenges. This in-depth analysis enabled the customer to make informed decisions, ensuring their infrastructure not only satisfied current needs but was also adaptable for future advancements
What is CVE-2018-11784? CVE-2018-11784 is an open redirect vulnerability impacting several versions of Apache Tomcat, specifically versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33, and 7.0.23 to 7.0.90. This vulnerability arises when the default servlet in Apache Tomcat incorrectly handles redirects to directories. For instance, if a user requests '/foo', the server might improperly redirect them to '/foo/' using a specially crafted URL, allowing an attacker to redirect to any URI. This could be exploited to redirect users to malicious websites without their knowledge. The Significance of Mitigating Open Redirect Vulnerabilities Open redirect vulnerabilities are crucial to mitigate because they can serve as a mechanism in phishing attacks, misleading users about the authenticity of a website. When exploited, these vulnerabilities allow attackers to redirect users from legitimate websites to malicious ones. This redirection can deceive users into believ
For more than a decade, digital transformation has been the talk within businesses. One of the core elements in this journey is the migration to the public cloud, which adopts new ways of thinking and working the infrastructure and applications. This journey centers on automating infrastructure and application provisioning, rapidly detecting and responding in operations, containerizing applications, and leveraging serverless technology or other services from cloud providers for rapid prototyping, innovation, and adoption. Executives prioritize this initiative to expedite the pace of innovation, save on capital costs and time to set up infrastructure and realize new ways of delivering services. In the urgency to be part of the wave, some companies rush to adopt an “all-in” approach too quickly without sufficient due diligence. This presents a risk of failure, beyond a technical point of view which is the financial viewpoint. One of the elements that customers must realize is that they n
FortiWeb SOCaaS: Comprehensive 24/7 Protection, Security Hardening, Incident Response, and Cloud Service Dashboard In an era where cyber threats continue to rise in frequency and sophistication, securing web applications is more critical than ever. Enterprises are increasingly turning to managed security services like FortiWeb SOCaaS (Security Operations Center as a Service) to protect their digital assets. With features such as 24/7 protection, security hardening, incident response, and a powerful cloud service dashboard, FortiWeb SOCaaS offers a robust solution for managing the complexities of modern web application security. The Need for FortiWeb SOCaaS Web applications are among the most exposed components of any IT infrastructure, making them prime targets for cyberattacks. From SQL injections to cross-site scripting and distributed denial-of-service (DDoS) attacks, the risks are diverse and ever-evolving. FortiWeb SOCaaS addresses these challenges by delivering a co
FortiWeb Security Alert: CVE-2024-3651 Vulnerability in idna.encode The Impact of CVE-2024-3651 In the realm of web security, vulnerabilities can often lead to severe consequences if left unaddressed. One such critical issue is identified by CVE-2024-3651, a vulnerability that significantly impacts web applications by exposing them to potential denial-of-service (DoS) attacks and remote code execution (RCE). This essay explores the nature of CVE-2024-3651, its implications for web security, and the importance of addressing such vulnerabilities to maintain robust and secure web applications. CVE-2024-3651 is categorized as a critical vulnerability primarily due to its origin in the improper validation of URL, header, and argument lengths within web applications. Web applications rely on numerous parameters passed through URLs, headers, and request bodies to function correctly. These inputs are crucial for processing requests, managing sessions, and delivering co
What is CVE-2023-34434? CVE-2023-34434 is a critical security vulnerability identified in Apache InLong, an open-source data collection and processing platform. This vulnerability affects versions 1.4.0 through 1.7.0 of Apache InLong. It is classified as a deserialization flaw, which can be exploited to bypass security mechanisms and gain unauthorized access to arbitrary files. The issue was resolved in Apache InLong version 1.8.0. The Significance of CVE-2023-34434 Deserialization of untrusted data is a critical security concern that can lead to unauthorized access and system compromise. This vulnerability within Apache InLong could enable attackers to manipulate or steal data by bypassing existing logic controls, making it a priority to address. The vulnerability is rooted in the deserialization process, which is the method of converting data from a serialized format back into an object or data structure. Deserialization is a common practice
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.