FortiGuard Labs (Fortinet) — Threat Research
fortinet-fortiguard-blog · B · candidate
https://www.fortinet.com/blog/threat-research
Added 2026-08-16 as this run's single new candidate. Named original-research primary for the Evooo1Bot Linux-botnet entry published this run, and the originating lab for several IoT/Mirai-derivative writeups cited by earlier fires without the publisher being tracked. Article bodies are client-rendered: a follow-up research pass reported the raw-HTML bridge returning only the page shell while WebFetch rendered it, but the main agent reached the full article body through `fetch_source.py url` on the same host later in the same run, so treat the bridge as working and WebFetch as the fallback. No RSS feed identified yet — worth another look before promotion.
Cited in 14 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 10).
- Evooo1Bot: a Mirai-derived Linux botnet whose exploit arsenal reaches Confluence, WSO2 and Kubernetes ingress-nginx, and whose SSH dictionary is stocked with enterprise service accounts rather than router defaults2026-08-16
- The exploited surface this week was the management plane itself — VeloCloud Orchestrator, Secure FMC, Check Point SmartConsole, FortiOS SSL-VPN and exposed BMCs, and on several of them what the attacker obtained outlives the upgrade2026-08-02
- CVE-2025-68686 — FortiOS SSL-VPN: the fix for the symlink-persistence technique is itself bypassable, and CISA now lists it as exploited2026-07-28
- FortiBleed — first full tool-chain disclosure (FortigateSniffer, SNIFTRAN, GPU cracking cluster); Fortinet confirms no new CVE2026-06-23
- FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory2026-06-22
- FortiGuard documents C0XMO, a cross-platform Gafgyt variant propagating through a five-year-old DD-WRT UPnP flaw2026-06-08
- FIFA World Cup 2026 pre-event threat cluster: Android banking trojans in pirated streaming apps, plus a 13,000-domain fraud layer, ahead of the 11 June kick-off2026-06-08
- FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain2026-05-29
- FortiClient EMS CVE-2026-35616 actively exploited to push EKZ Infostealer through trusted endpoint-management channel2026-05-29
- CVE-2026-32996 & CVE-2026-32997 — Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance2026-05-29
- CVE-2026-35616 — Fortinet FortiClient EMS pre-auth bypass, exploited to push EKZ Infostealer down the management channel2026-05-25
- CVE-2026-44277 / CVE-2026-26083 — Fortinet FortiAuthenticator and FortiSandbox unauthenticated RCE2026-05-13
- CERTFR-2026-AVI-0572 — Centreon Infra Monitoring: RCE / SQLi / XSS cluster (April 2026 bulletin)2026-05-13
- CVE-2026-44277 / CVE-2026-26083 — Fortinet FortiAuthenticator and FortiSandbox unauthenticated RCE2026-05-11