|
|
| FortiGuard Labs | FortiGuard Center - Outbreak Alerts |
QuickFox Supply Chain Attack
FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily used by overseas Chinese users. Attackers tampered with official Windows installers to deploy a custom backdoor tracked as FDMTP, enabling selective victim profiling and post-compromise access. The campaign has reportedly been active since August 2025 before being publicly disclosed in August 2026. |
WP2Shell RCE
FortiGuard Labs continues to detect exploitation attempts targeting the WP2Shell attack chain (CVE-2026-63030 and CVE-2026-60137), a critical unauthenticated remote code execution (RCE) vulnerability affecting WordPress Core. Telemetry collected over the past seven days shows the highest volume of blocked attacks originating from or targeting Poland, Australia, Japan, the United States, and Turkey. |
Palo Alto Networks PAN-OS GlobalProtect Auth Bypass
Attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass vulnerability to gain unauthorized VPN access to exposed Palo Alto Networks firewalls. An attacker who successfully exploits CVE-2026-0257 can:
- Establish unauthorized VPN sessions through affected GlobalProtect gateways.
- Bypass authentication controls without valid user credentials.
- Gain network-level access typically reserved for authenticated VPN users.
- Potentially facilitate further reconnaissance, lateral movement, or follow-on attacks within the victim environment. |
| | Distributed by aarss.com. |
|
|
|
|
|
Joe's Cable Contact Site |
Joe's Cable is always looking for new clients. You may contact us
via Telephone, E-Mail, or by filling out the form on this page.
Telephone: 201-289-7613
E-Mail:
contact@joescable.com
Web Form: |
|
|
|
|