Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Fortinet Edge Exploitation Hits Thai Broadband Provider: FortiGate Compromise Detection and Hardening Guide
Introduction SecurityWeek reports that a Thai broadband provider was compromised through a vulnerability in its Fortinet infrastructure. The...
CISA KEV Alert: CVE-2026-20079 (Cisco, CVSS 10.0) Plus Citrix and Fortinet Flaws Under Active Exploitation — Federal Patch Deadline September 12, 2026
Introduction On Wednesday, CISA added three vulnerabilities — one each impacting Cisco, Citrix, and Fortinet — to its Known Exploited Vulner...
CVE-2026-84387: Fortinet FortiSandbox cronValue Command Injection (ZDI-26-645) — Detection and Remediation Guide
The Short Version The Zero Day Initiative has published ZDI-26-645, disclosing a command injection vulnerability in Fortinet FortiSandbox tr...
CISA KEV Adds CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, CVE-2026-20079: Fortinet, Citrix, Chrome, and Cisco FMC Under Active Exploitation — Defense Guide
Four More KEV Entries: Fortinet, NetScaler, Chrome V8, and Cisco FMC Are Being Exploited Right Now On September 9, 2026, CISA added four vul...
CVE-2025-25249: Fortinet FortiOS, FortiSwitchManager & FortiSASE Heap Overflow Under Active Exploitation — Detection and Remediation Guide
What Happened On September 9, 2026, CISA added CVE-2025-25249 to the Known Exploited Vulnerabilities (KEV) catalog, confirming what many of ...
Edge Infrastructure Under Siege: Defending Ivanti, Fortinet, and Palo Alto Networks Perimeters Against Converging Threat Actors
Introduction For two years, the headlines have told a tidy story: China-nexus actors are hammering edge devices from Ivanti, Fortinet, and P...
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws: Detection and Hardening Guide for Critical Infrastructure Defenders
Introduction Cybersecurity and intelligence agencies from South Korea and the United States have issued a joint warning on Gunra, an encrypt...
CVE-2025-68686: Fortinet FortiOS Symlink Bypass — Detection and Remediation
CVE-2025-68686: Fortinet FortiOS Symlink Bypass — Detection and Remediation On July 27, 2026, CISA added CVE-2025-68686 to the Known Exploit...
CISA KEV Alert: Active Exploitation of Fortinet FortiSandbox and Microsoft SharePoint Flaws
CISA Adds Critical Fortinet and Microsoft Flaws to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has sounded ...