Fortiguard Labs

Latest Security Updates

Latest Report Image

signalreport-logo Threat Signal

Jul 29, 2026

WordPress Core Unauthenticated RCE (WP2Shell)

Latest Report Image

fortiguardblog-logo Threat Research

Jul 22, 2026

Inside a TrickBot Variant Using DNS Tunneling for C2

Latest Report Image

outbreakalert-logo Outbreak Alert

Jul 21, 2026

Palo Alto Networks PAN-OS GlobalProtect Auth Bypass

Outbreak Reports

outbreakalert-logo Outbreak Alert

Palo Alto Networks PAN-OS GlobalProtect Auth Bypass

Attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass vulnerability to gain unauthorized VPN access to exposed Palo Alto...

1 week ago

outbreakalert-logo Outbreak Alert

Joomla SP Page Builder RCE

FortiGuard Labs continues to observe active exploitation of CVE-2026-48908, a critical unauthenticated remote code execution vulnerability...

1 week ago

outbreakalert-logo Outbreak Alert

Ivanti Sentry OS Command Injection Vulnerability

FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical details and...

3 weeks ago

outbreakalert-logo Outbreak Alert

Langflow Unauth RCE Attack

FortiGuard Labs has observed a significant uptick in attacks targeting Langflow, leveraging a recently discovered authentication bypass...

3 weeks ago

outbreakalert-logo Outbreak Alert

HTTP/2 Bomb Denial-of-Service Vulnerability

Security researchers have disclosed a new denial-of-service (DoS) attack technique dubbed HTTP/2 Bomb, tracked as CVE-2026-49975, that affects...

1 month ago

outbreakalert-logo Outbreak Alert

Citrix NetScaler Memory Overread Vulnerability

Exploitation activity targeting vulnerable Citrix NetScaler ADC and Gateway appliances remains persistent and widespread, with FortiGuard Labs...

2 months ago

outbreakalert-logo Outbreak Alert

Cisco ASA and FTD Firewall RCE

Critical zero-day vulnerabilities affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD)...

3 months ago

outbreakalert-logo Outbreak Alert

SmarterTools SmarterMail RCE

An actively targeted vulnerability has been identified in SmarterTools SmarterMail, tracked as CVE-2025-52691, with a CVSS score of 10.0...

3 months ago

outbreakalert-logo Outbreak Alert

React2Shell Remote Code Execution

React2Shell is a critical unauthenticated remote code execution (RCE) vulnerability affecting React Server Components (RSC) and frameworks that...

3 months ago

outbreakalert-logo Outbreak Alert FEATURED

Outbreak Alert- Annual Report 2025

In 2025, the FortiGuard Labs team processed and blocked 3.8 trillion vulnerability exploitation attempts, preventing 2.71 billion malware...

4 months ago

Threat Research

fortiguardblog-logo Threat Research

Inside a TrickBot Variant Using DNS Tunneling for C2

FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and...

1 week ago

fortiguardblog-logo Threat Research

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.      

2 weeks ago

fortiguardblog-logo Threat Research

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs, steganography, and evasive C2.      

4 weeks ago

fortiguardblog-logo Threat Research

From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach

See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation, and led to Redshift breach activity detected by...

1 month ago

fortiguardblog-logo Threat Research

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and...

1 month ago

fortiguardblog-logo Threat Research

Cybercriminals Are Targeting the FIFA World Cup 2026

FortiGuard Labs research shows how cybercriminals are exploiting the demand for the FIFA World Cup 2026 through phishing, fake tickets, malware,...

1 month ago

fortiguardblog-logo Threat Research

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet...

1 month ago

fortiguardblog-logo Threat Research

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data      

2 months ago

fortiguardblog-logo Threat Research

Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise

FortiGuard Labs analyzed several P2PInfect compromises in GKE clusters, showing how exposed Redis instances can enable persistent botnet...

2 months ago

fortiguardblog-logo Threat Research

PureLogs: Delivery via PawsRunner Steganography

FortiGuard Labs has analyzed a steganography-based malware campaign that uses PawsRunner to deliver the PureLogs infostealer, highlighting...

2 months ago

Threat Signals

signalreport-logo Threat Signal

WordPress Core Unauthenticated RCE (WP2Shell)

FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack...

1 day ago

signalreport-logo Threat Signal

PTC Windchill & FlexPLM RCE

A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited...

3 days ago

signalreport-logo Threat Signal

Ubiquiti UniFi OS RCE

Multiple critical vulnerabilities affecting Ubiquiti UniFi OS can be chained together to achieve unauthenticated remote code execution (RCE) with...

3 weeks ago

signalreport-logo Threat Signal

Splunk Enterprise Authentication Bypass Vulnerability

A critical authentication bypass vulnerability, CVE-2026-20253 (CVSS 9.8), affects Splunk Enterprise versions 10.0.x and 10.2.x. The flaw stems...

1 month ago

signalreport-logo Threat Signal

Oracle PeopleSoft Zero-Day

Google Threat Intelligence Group (GTIG) and Mandiant have identified an active compromise and extortion campaign attributed to ShinyHunters...

1 month ago

signalreport-logo Threat Signal

npm Supply Chain Cryptocurrency Malware

Researchers have identified a large-scale software supply chain campaign targeting the npm ecosystem, leveraging malicious JavaScript packages to...

1 month ago

signalreport-logo Threat Signal

Check Point VPN Authentication Bypass Vulnerability

A critical authentication bypass vulnerability, CVE-2026-50751 (CVSS 9.3), is being actively exploited against vulnerable Check Point Remote...

1 month ago

FortiGuard Labs

AI-powered threat intelligence research, securing customers across the entire attack surface.

AI<br>Security Center

AI
Security Center

Securing AI systems while applying AI to cyber defense.

Learn more
Quantum<br>Security Center

Quantum
Security Center

Quantum-safe cryptography for the post-quantum era.

Learn more
Zero-Day<br>Security Center

Zero-Day
Security Center

Discovering and responsibly disclosing zero-day flaws.

Learn more
Sovereign<br>Cyber Initiative

Sovereign
Cyber Initiative

Cyber resilience for nations and their critical assets.

Learn more
Critical Infrastructure<br>Security

Critical Infrastructure
Security

Defending power, healthcare, and financial systems.

Learn more

Services

Comprehensive security services designed to protect your infrastructure, applications, and data at every layer.

Certifications

  • av comparatives logo
  • common criteria logo
  • nss labs logo
  • vb logo
  • mitre logo