Let me remind you that we also wrote that Hackers leaked credentials of 500,000 Fortinet VPN accounts to the public.
Fortinet developers reported a critical vulnerability in their products earlier this week, and released patches for a dangerous problem that was already under attack at that time.
Authentication bypass using alternative path or channel [CWE-88] in FortiOS and FortiProxy allows [...]Fortinet — is an American company that specializes in the development and promotion of software, solutions and services in the field of information security.
In the Joint Cybersecurity Advisory (CSA) published, the agencies warn admins and users that the state-sponsored hacking groups are “likely” exploiting Fortinet FortiOS vulnerabilities CVE-2018-13379, CVE-2020-12812, and CVE-2019-5591.
“APT groups can use these vulnerabilities and other [...]