CISA Advisories

Unpatched FortiMail 0-Day 🚨 + $387M Crypto Heist via Security Gear 💸

Today's two biggest security stories share an uncomfortable theme: the tools companies buy to stay safe are becoming the front door for attackers. Here's what you need to know.

FortiMail Zero-Day: Your Email Gateway Is Under Attack, and There's No Patch Yet

Fortinet is warning that hackers are actively exploiting a critical flaw (rated 9.8 out of 10) in FortiMail, the email security appliance many businesses use to filter spam and phishing. The bug lets an attacker with no password at all send specially crafted web requests that plant files and run their own code on the device. Versions 7.2.0 through 8.0.1 are affected, and fixed versions aren't out yet. Why it matters: the box guarding your inbox could be quietly handing over the keys. If your organization runs FortiMail, lock down the management interface to trusted networks only (or disable the IBE feature) today. CISA has given federal agencies until October 4 to act, a sign of how serious this is.

Read more

The $387.5 Million Heist That Started With a Security Product

Crypto exchange Bitget lost $387.5 million after attackers broke in through an unknown flaw in a third-party security product, the very kind of tool meant to keep intruders out. The hackers sat inside for 25 days, moved to a second appliance, then reached the server that handles wallet withdrawals. From there, they used a custom tool to fake the risk checks and drained wallets in under three hours. Why it matters: security appliances often get less scrutiny than "real" servers, and attackers know it. Every business should monitor its firewalls, gateways, and VPNs as closely as its most sensitive systems, and keep critical safety checks separate from the systems they protect.

Read more

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts