🌐
The Hacker News
thehackernews.com › home › cybersecurity news
Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability
1 day ago - Fortinet reports active attacks exploiting CVE-2020-12812, a FortiOS SSL VPN flaw that can bypass two-factor authentication in specific LDAP setups.
🌐
Fortinet
fortinet.com › corporate › about-us › newsroom
Newsroom | Fortinet News Releases
Nov 5, 2025 Fortinet Reports Third Quarter 2025 Financial Results · News Release Archive · Aug 22, 2025 | Bleeping Computer Massive anti-cybercrime operation leads to over 1,200 arrests in Africa · Aug 19, 2025 | EdTech Magazine 4 SIEM Solutions ...
🌐
SecurityWeek
securityweek.com › home › news › fortinet warns of new attacks exploiting old vulnerability
Fortinet Warns of New Attacks Exploiting Old Vulnerability - SecurityWeek
2 days ago - Fortinet says threat actors are abusing CVE-2020-12812, an improper authentication vulnerability in FortiOS, in a fresh wave of attacks.
🌐
The Hacker News
thehackernews.com › search › label › Fortinet
Fortinet — Latest News, Reports & Analysis | The Hacker News
Cybersecurity researchers are sounding the alert about an authentication bypass vulnerability in Fortinet FortiWeb Web Application Firewall (WAF) that could allow an attacker to take over admin accounts and completely compromise a device.
🌐
Cyber Security News
cybersecuritynews.com › home › cyber security news › hackers exploiting three-year-old fortigate vulnerability to bypass 2fa on firewalls
Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls
1 week ago - Cybercriminals are actively abusing a long-patched Fortinet FortiGate flaw from July 2020, slipping past two-factor authentication (2FA) on firewalls and potentially granting unauthorized access to VPNs and admin consoles.
🌐
BleepingComputer
bleepingcomputer.com › home › news › security › fortinet warns of 5-year-old fortios 2fa bypass still exploited in attacks
Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks
2 days ago - Fortinet has warned customers that threat actors are still actively exploiting a critical FortiOS vulnerability that allows them to bypass two-factor authentication (2FA) when targeting vulnerable FortiGate firewalls.
🌐
The Hacker News
thehackernews.com › home › cybersecurity news
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass
2 weeks ago - Threat actors have begun to exploit two newly disclosed security flaws in Fortinet FortiGate devices, less than a week after public disclosure. Cybersecurity company Arctic Wolf said it observed active intrusions involving malicious single sign-on ...
🌐
Fortinet
fortinet.com › blog
Fortinet Blog - Broad, Integrated, Automated Cybersecurity
Explore the latest cybersecurity trends and innovations, leading edge threat intelligence from FortiGuard Labs, Fortinet executive insights, and customer perspectives.
Find elsewhere
🌐
Techzine Global
techzine.eu › news › security › attackers exploit five-year-old fortinet vulnerability
Attackers exploit five-year-old Fortinet vulnerability - Techzine Global
2 days ago - Fortinet warns of active attacks on a five-year-old vulnerability in FortiOS that bypasses two-factor authentication.
🌐
Fortinet TV
fortinet-tv.com
Fortinet TV | Cybersecurity News Events Trends & Insight Videos
Fortinet videos covering the latest cybersecurity news, events, trends, strategy, and insights from our leading industry experts, customers and partners.
🌐
Security Affairs
securityaffairs.com › 186117 › security › five-year-old-fortinet-fortios-ssl-vpn-flaw-actively-exploited.html
Five-year-old Fortinet FortiOS SSL VPN flaw actively exploited
5 days ago - Fortinet researchers observed “recent abuse” of a five-year-old security vulnerability, tracked as CVE-2020-12812 (CVSS score: 5.2), in FortiOS SSL VPN.
🌐
Cybersecurity Dive
cybersecuritydive.com › news › fortigate-devices-targeted-with-malicious-sso-logins › 808132
FortiGate devices targeted with malicious SSO logins | Cybersecurity Dive
2 weeks ago - Fortinet said the flaws were originally discovered by two members of its product security team. The flaws, tracked as CVE-2025-59718 and CVE-2025-59719, allow an attacker to bypass the FortiCloud SSO authentication using a crafted SAML message ...
🌐
SC Media
scworld.com › sc media › threat management › intrusions involving old fortinet fortios ssl vpn bug underway
Intrusions involving old Fortinet FortiOS SSL VPN bug underway | SC Media
5 days ago - Threat actors have launched attacks exploiting the half-decade-old medium-severity improper authentication vulnerability in Fortinet's FortiOS SSL VPN, tracked as CVE-2020-12812, according to Security Affairs.
🌐
Fortinet
fortinet.com › fortiguard › outbreak-alert
View the latest outbreak alerts on cyber-attacks | FortiGuard Labs
View the latest outbreak alerts tracked by FortiGuard Labs. View the full Outbreak Alert report to understand the impact and outcome of the attack. From the latest Colonial Pipeline ransomware attack to the Microsoft Exchange zero-day exploits.
🌐
CISA
cisa.gov › news-events › alerts › 2025 › 11 › 14 › fortinet-releases-security-advisory-relative-path-traversal-vulnerability-affecting-fortiweb
Fortinet Releases Security Advisory for Relative Path Traversal Vulnerability Affecting FortiWeb Products | CISA
CISA is aware of the exploitation of two vulnerabilities, CVE-2025-64446 and CVE-2025-58034, in Fortinet FortiWeb, a web application firewall. CISA is also aware that threat actors could exploit CVE-2025-64446 as an initial access vector and then chain CVE-2025-58034 to escalate privileges ...
🌐
OpenPR
openpr.com › news › 4329116 › cybersecurity-market-to-reach-usd-556-billion-by-2032-cagr-12
Cybersecurity Market to Reach USD 556 Billion by 2032 | CAGR 12% | Key Players: Fortinet, IBM, Microsoft, Palo Alto Networks
5 days ago - August 2025: Imprivata acquired Verosint, adding AI-powered identity threat detection and response capabilities to its cybersecurity portfolio. ✅ July 2025: Jamf was taken private by Francisco Partners in a $2.2 billion deal, reinforcing ...
🌐
BleepingComputer
bleepingcomputer.com › home › news › security › over 25,000 forticloud sso devices exposed to remote attacks
Over 25,000 FortiCloud SSO devices exposed to remote attacks
1 week ago - Fortinet noted on December 9th, when it patched the security flaw tracked as CVE-2025-59718 (FortiOS, FortiProxy, FortiSwitchManager) and CVE-2025-59719 (FortiWeb), that the vulnerable FortiCloud SSO login feature is not enabled until admins ...