Fortinet has issued a critical alert to its customers concerning a severe OS command injection vulnerability identified in the FortiSIEM report server. Tracked as CVE-2023-36553, this flaw enables remote, unauthenticated attackers to execute commands by manipulating API requests. Rated with a critical severity score of 9.3 by Fortinet's team and 9.8 by NIST, this vulnerability poses a significant threat. FortiSIEM, a robust cybersecurity solution, is widely utilized across diverse sectors such as healthcare, finance, retail, e-commerce, and government, offering heightened visibility and control over security posture. The vulnerability, a variant of the previously addressed CVE-2023-34992 issue, stems from inadequate neutralization of special elements within API requests. Exploiting this oversight can authorize the execution of unauthorized commands, potentially leading to data breaches or manipulation of systems. Fortinet strongly advises administrators to upgrade affected FortiSIEM versions (ranging from 4.7 to 5.4) to versions 6.4.3, 6.5.2, 6.6.4, 6.7.6, 7.0.1, or 7.1.0, emphasizing the urgency for immediate action. Fortinet's products, including firewalls and intrusion detection systems, are attractive targets for sophisticated hacking groups. Recent reports have linked exploits in Fortinet products to instances of cyber-espionage affecting U.S. aeronautical firms and Chinese clusters. Notably, government networks have also faced compromises due to zero-day vulnerabilities found in Fortinet products, underscoring the critical need for robust security measures.
Charter Communications has confirmed a cybersecurity incident impacting millions of customers following a breach allegedly conducted by the ShinyHunters extortion gang. According t...
A critical Remote Code Execution (RCE) vulnerability has been identified in Samba, the widely used open-source SMB/CIFS file-sharing software for Linux and Unix systems. The flaw c...
A sophisticated cyber-espionage campaign linked to the Iran-aligned threat group Seedworm has targeted at least nine organizations across multiple countries during early 2026. The ...