Fortiguard Labs

Latest Security Updates

Latest Report Image

signalreport-logo Threat Signal

Aug 10, 2026

Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack

Latest Report Image

outbreakalert-logo Outbreak Alert

Aug 07, 2026

QuickFox Supply Chain Attack

Latest Report Image

fortiguardblog-logo Threat Research

Aug 04, 2026

QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

Outbreak Reports

outbreakalert-logo Outbreak Alert

QuickFox Supply Chain Attack

FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily...

4 days ago

outbreakalert-logo Outbreak Alert

WP2Shell RCE

FortiGuard Labs continues to detect exploitation attempts targeting the WP2Shell attack chain (CVE-2026-63030 and CVE-2026-60137), a critical...

1 week ago

outbreakalert-logo Outbreak Alert

Palo Alto Networks PAN-OS GlobalProtect Auth Bypass

Attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass vulnerability to gain unauthorized VPN access to exposed Palo Alto...

3 weeks ago

outbreakalert-logo Outbreak Alert

Joomla SP Page Builder RCE

FortiGuard Labs continues to observe active exploitation of CVE-2026-48908, a critical unauthenticated remote code execution vulnerability...

3 weeks ago

outbreakalert-logo Outbreak Alert

Ivanti Sentry OS Command Injection Vulnerability

FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical details and...

1 month ago

outbreakalert-logo Outbreak Alert

Langflow Unauth RCE Attack

FortiGuard Labs has observed a significant uptick in attacks targeting Langflow, leveraging a recently discovered authentication bypass...

1 month ago

outbreakalert-logo Outbreak Alert

HTTP/2 Bomb Denial-of-Service Vulnerability

Security researchers have disclosed a new denial-of-service (DoS) attack technique dubbed HTTP/2 Bomb, tracked as CVE-2026-49975, that affects...

1 month ago

outbreakalert-logo Outbreak Alert

Citrix NetScaler Memory Overread Vulnerability

Exploitation activity targeting vulnerable Citrix NetScaler ADC and Gateway appliances remains persistent and widespread, with FortiGuard Labs...

2 months ago

outbreakalert-logo Outbreak Alert

Cisco ASA and FTD Firewall RCE

Critical zero-day vulnerabilities affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD)...

3 months ago

outbreakalert-logo Outbreak Alert FEATURED

Outbreak Alert- Annual Report 2025

In 2025, the FortiGuard Labs team processed and blocked 3.8 trillion vulnerability exploitation attempts, preventing 2.71 billion malware...

5 months ago

Threat Research

fortiguardblog-logo Threat Research

QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting,...

1 week ago

fortiguardblog-logo Threat Research

Inside a TrickBot Variant Using DNS Tunneling for C2

FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and...

2 weeks ago

fortiguardblog-logo Threat Research

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.      

3 weeks ago

fortiguardblog-logo Threat Research

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs, steganography, and evasive C2.      

1 month ago

fortiguardblog-logo Threat Research

From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach

See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation, and led to Redshift breach activity detected by...

1 month ago

fortiguardblog-logo Threat Research

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and...

2 months ago

fortiguardblog-logo Threat Research

Cybercriminals Are Targeting the FIFA World Cup 2026

FortiGuard Labs research shows how cybercriminals are exploiting the demand for the FIFA World Cup 2026 through phishing, fake tickets, malware,...

2 months ago

fortiguardblog-logo Threat Research

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet...

2 months ago

fortiguardblog-logo Threat Research

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data      

2 months ago

fortiguardblog-logo Threat Research

Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise

FortiGuard Labs analyzed several P2PInfect compromises in GKE clusters, showing how exposed Redis instances can enable persistent botnet...

2 months ago

Threat Signals

signalreport-logo Threat Signal

Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack

Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with...

1 day ago

signalreport-logo Threat Signal

PTC Windchill & FlexPLM RCE

A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited...

2 weeks ago

signalreport-logo Threat Signal

Ubiquiti UniFi OS RCE

Multiple critical vulnerabilities affecting Ubiquiti UniFi OS can be chained together to achieve unauthenticated remote code execution (RCE) with...

1 month ago

signalreport-logo Threat Signal

Splunk Enterprise Authentication Bypass Vulnerability

A critical authentication bypass vulnerability, CVE-2026-20253 (CVSS 9.8), affects Splunk Enterprise versions 10.0.x and 10.2.x. The flaw stems...

1 month ago

signalreport-logo Threat Signal

Oracle PeopleSoft Zero-Day

Google Threat Intelligence Group (GTIG) and Mandiant have identified an active compromise and extortion campaign attributed to ShinyHunters...

1 month ago

signalreport-logo Threat Signal

npm Supply Chain Cryptocurrency Malware

Researchers have identified a large-scale software supply chain campaign targeting the npm ecosystem, leveraging malicious JavaScript packages to...

1 month ago

FortiGuard Labs

AI-powered threat intelligence research, securing customers across the entire attack surface.

AI<br>Security Center

AI
Security Center

Securing AI systems while applying AI to cyber defense.

Learn more
Quantum<br>Security Center

Quantum
Security Center

Quantum-safe cryptography for the post-quantum era.

Learn more
Zero-Day<br>Security Center

Zero-Day
Security Center

Discovering and responsibly disclosing zero-day flaws.

Learn more
Sovereign<br>Cyber Initiative

Sovereign
Cyber Initiative

Cyber resilience for nations and their critical assets.

Learn more
Critical Infrastructure<br>Security

Critical Infrastructure
Security

Defending power, healthcare, and financial systems.

Learn more

Services

Comprehensive security services designed to protect your infrastructure, applications, and data at every layer.

Certifications

  • av comparatives logo
  • common criteria logo
  • nss labs logo
  • vb logo
  • mitre logo