Werbefrei,
für immer!
Fortinet Technical Tips
RSS-Fehler: Retrieved unsupported status code "404"
Fortinet Firmware Updates
- FortiCamera 2.2.3 B0151 and release notes are available for download from the Support site : https://support.fortinet.com
- FortiAIOps 3.4.1 B0275 and release notes are available for download from the Support site : https://support.fortinet.com
- FortiNAC-F 7.6.7 B0976 and release notes are available for download from the Support site : https://support.fortinet.com
- FortiVoiceUCDesktop 8.0.0 B0067 and release notes are available for download from the Support site : https://support.fortinet.com
- FortiADCManager 8.0.1 B0015 and release notes are available for download from the Support site : https://support.fortinet.com
- FortiSwitch 7.6.8 B1164 and release notes are available for download from the Support site : https://support.fortinet.com
- FortiWeb 8.0.6 B0116 and release notes are available for download from the Support site : https://support.fortinet.com
- FortiDeceptor 6.3.0 B0465 and release notes are available for download from the Support site : https://support.fortinet.com
- FortiMail 7.4.7 B0625 and release notes are available for download from the Support site : https://support.fortinet.com
- FortiVoice 8.0.0 B0114 and release notes are available for download from the Support site : https://support.fortinet.com
Fortinet Thread Blog
- FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and obfuscation techniques
- FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.
- FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs, steganography, and evasive C2.
- See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation, and led to Redshift breach activity detected by FortiCNAPP
- FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remote access.
- FortiGuard Labs research shows how cybercriminals are exploiting the demand for the FIFA World Cup 2026 through phishing, fake tickets, malware, impersonation, and credential theft.
- FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.
- FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data
- FortiGuard Labs analyzed several P2PInfect compromises in GKE clusters, showing how exposed Redis instances can enable persistent botnet enrollment, dormancy, and cloud runtime risk.
- FortiGuard Labs has analyzed a steganography-based malware campaign that uses PawsRunner to deliver the PureLogs infostealer, highlighting evolving delivery methods and detection strategies.
Cert Bund News
- [NEU] [hoch] Apache Airflow FAB provider: Schwachstelle ermöglicht Erlangen von AdministratorrechtenEin entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Airflow FAB provider ausnutzen, um Sicherheitsmaßnahmen zu umgehen und Administratorrechte zu erlangen.
- Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift Container Platform ausnutzen, um einen Denial of Service Angriff durchzuführen.
- Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Podman ausnutzen, um Informationen offenzulegen.
- Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um beliebigen Programmcode auszuführen.
- Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial-of-Service-Zustand zu verursachen.
- Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, Microsoft Visual Studio Code, Microsoft .NET Framework und Microsoft .NET ausnutzen, um beliebigen Programmcode auszuführen, um Daten zu manipulieren, um seine […]
- Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
- Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL und LibreSSL ausnutzen, um potentiell beliebigen Code auszuführen, einen Denial of Service-Zustand zu verursachen und vertrauliche Informationen offenzulegen.
- Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
- Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in GNU libc ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.
Microsoft Exchange Team Blog
RSS-Fehler: Retrieved unsupported status code "404"
MSXFAQ Newsfeed
- 08. Jul 26 Simple SAML Sample – Beispiel-App einer einfachen SAML-Anmeldung für 3rd Party Dienste über EntraID
- 26. Jun 26 BreakGlassApp – So können Sie jeden User per AppRegistration im Notfall zum GlobalAdmin machen
- 19. Jun 26 Exchange Online EWS Abschaltung 2026 – Roadmap der EWS Abschaltung in Exchange Online mit Änderungen und Aktionen ergänzt
- 17. Jun 26 EEMS – Exchange Emergency Mitigation Service – Ablaufende RootCAs treffen nicht nur UEFI-Boot, sondern auch EEMS
- 15 Jun 26 Exchange Online als Nebeneingang für Mailempfang – "Ghost-Sender" ist keine Lücke in Exchange Online sondern ein Konfigurationsfehler des Administrators
- 14. Jun 26 Kalendersharing und REST – Seit Sommer 26 werden in Exchange Online Kalender von Postfächern in den Kalender des Stellvertreters repliziert
- 12. Jun 26 Exchange CU und RequireSSL – Wenn ein CU Update schief läuft und wie ich die Ursache ermittelt habe
- 11. Jun 26 Get-DLLastUsed – Ermitteln, welche Exchange Online Verteilerliste wann zuletzt per Mail angesprochen wurde
- 10. Jun 26 Autodiscover – getaccounttype – "New Outlook" nutzt einen anderen Webservice um zu ermitteln, ob es ein Postfach in Exchange Online, über IMAP4 oder bei GMail/Yahoo ist
- 09 Jun 26 Exchange Server SE Updates SU7 öffentlich, Ex2016/2019 Updates nur mit ESU. 7 Sicherheitslücken und EEMS wird unbrauchbar für alte Versionen