FortiGuard Labs (Fortinet), Threat Research
fortinet-fortiguard-blog · B · active
https://www.fortinet.com/blog/threat-research
Added 2026-08-16 as this run's single new candidate. Named original-research primary for the Evooo1Bot Linux-botnet entry published this run, and the originating lab for several IoT/Mirai-derivative writeups cited by earlier fires without the publisher being tracked. Article bodies are client-rendered: a follow-up research pass reported the raw-HTML bridge returning only the page shell while WebFetch rendered it, but the main agent reached the full article body through `fetch_source.py url` on the same host later in the same run, so treat the bridge as working and WebFetch as the fallback. No RSS feed identified yet, worth another look before promotion. | 2026-08-16 weekly: candidate -> active. The state digest counted 10 distinct contributing runs, well past the 3-run promotion bar; promoted mechanically from the counted evidence per the allocation rule rather than by eyeball.
Cited in 10 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 6).
- Evooo1Bot: a Mirai-derived Linux botnet whose exploit arsenal reaches Confluence, WSO2 and Kubernetes ingress-nginx, and whose SSH dictionary is stocked with enterprise service accounts rather than router defaults2026-08-16
- CVE-2025-68686, FortiOS SSL-VPN: the fix for the symlink-persistence technique is itself bypassable, and CISA now lists it as exploited2026-07-28
- FortiBleed, 73,932 internet-facing FortiGate devices exposed, Russian-speaking group cracking credentials into Active Directory2026-06-18
- FortiGuard documents C0XMO, a cross-platform Gafgyt variant propagating through a five-year-old DD-WRT UPnP flaw2026-06-08
- FIFA World Cup 2026 pre-event threat cluster: Android banking trojans in pirated streaming apps, plus a 13,000-domain fraud layer, ahead of the 11 June kick-off2026-06-08
- FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain2026-05-29
- FortiClient EMS CVE-2026-35616 actively exploited to push EKZ Infostealer through trusted endpoint-management channel2026-05-29
- CVE-2026-32996 & CVE-2026-32997, Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance2026-05-29
- CVE-2026-44277 / CVE-2026-26083, Fortinet FortiAuthenticator and FortiSandbox unauthenticated RCE2026-05-13
- CERTFR-2026-AVI-0572, Centreon Infra Monitoring: RCE / SQLi / XSS cluster (April 2026 bulletin)2026-05-13