<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>FortiGuard Labs | FortiGuard Center - Threat Signal Report</title><link>https://fortiguard.fortinet.com/rss/threatsignal.xml</link><description>The Threat Signal created by the FortiGuard Labs is intended to provide you with insight on emerging issues that are trending within the cyber threat landscape. The Threat Signal will provide concise technical details about the issue, mitigation recommendations and a perspective from the FortiGuard Labs team in an FAQ style format.</description><docs>http://www.rssboard.org/rss-specification</docs><generator>python-feedgen</generator><lastBuildDate>Fri, 11 Sep 2026 09:45:08 +0000</lastBuildDate><pubDate>Fri, 11 Sep 2026 09:45:08 -0700</pubDate><item><title>Orkes Conductor Evaluator Remote Code Execution</title><link>https://fortiguard.fortinet.com/threat-signal-report/6527</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Vulnerability?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     Attackers are actively targeting Orkes Conductor servers vulnerable to CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in its GraalVM script evaluators. FortiGuard telemetry is observing active attack attempts targeting vulnerable Orkes Conductor deployments. In the last 24 hours, FortiGuard IPS blocked 1,290 attack attempts, representing a 132% increase in daily activity. Over the last seven days, 6,696 attempts were blocked, with activity increasing 17% week over week.
     <br/>
     <br/>
     The highest volumes of observed attack activity originated from Germany, Hong Kong, Indonesia, the United Arab Emirates, and India.
     <br/>
     <br/>
     The vulnerability allows an unauthenticated attacker to submit a malicious workflow definition containing JavaScript or Python expressions to the Conductor workflow API. Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process.
     <br/>
     <br/>
     Public proof-of-concept exploit code is available, including a working exploit targeting Conductor v3.23.0. Exploit material has also been published through Exploit-DB, increasing the likelihood of opportunistic scanning and exploitation of exposed deployments.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     Organizations using affected versions should upgrade to Conductor 3.30.2 or later, which addresses the vulnerability.
     <br/>
     <br/>
     Until systems can be upgraded:
     <br/>
     • Restrict external access to Conductor workflow API endpoints.
     <br/>
     • Place Conductor instances behind appropriate network access controls and segmentation.
     <br/>
     • Do not expose vulnerable Conductor services directly to the Internet.
     <br/>
     • Monitor for suspicious workflow submissions and unexpected command execution originating from the Conductor process.
     <br/>
     • Review systems running vulnerable versions for signs of unauthorized command execution.
     <br/>
     <br/>
     Because the vulnerability is unauthenticated and remotely exploitable, Internet-exposed instances should be treated as a high priority for remediation.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • FortiGuard IPS Service: Detects and blocks network-based exploitation attempts targeting the Orkes Conductor vulnerability, including malicious requests attempting to trigger remote code execution.
     <a href="https://www.fortiguard.com/encyclopedia/ips/61328" rel="noopener noreferrer nofollow" target="_blank">
      Intrusion Prevention | FortiGuard Labs
     </a>
     <br/>
     • FortiGuard Antivirus &amp; Behavior Detection: Detects and blocks malicious files, scripts, and payloads that may be delivered following successful exploitation.
     <br/>
     • FortiGuard Web Filtering: Helps block access to known malicious infrastructure and payload-hosting locations associated with post-exploitation activity.
     <br/>
     • FortiEDR: Detects suspicious post-exploitation behavior, including unauthorized command execution, process spawning, persistence, and other activity resulting from a compromised Conductor server.
    </p>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6527</guid><pubDate>Wed, 09 Sep 2026 22:13:01 -0700</pubDate></item><item><title>Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack</title><link>https://fortiguard.fortinet.com/threat-signal-report/6498</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Attack?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes.
     <br/>
     <br/>
     While the reported activity specifically references Rockwell Automation/Allen-Bradley MicroLogix PLCs, the targeting is not necessarily limited to these products, and other internet-facing PLCs may also be at risk.
     <br/>
     <br/>
     The activity does not involve a specific CVE. Instead, attackers are taking advantage of Internet-exposed PLCs, weak or default credentials, and inadequate access controls to obtain unauthorized access to OT environments.
     <br/>
     <br/>
     Once access to an exposed PLC is obtained, attackers may manipulate configurations, operating parameters, or connected industrial processes. Such access can interfere with normal operations and potentially affect the availability and reliability of water and wastewater services.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • Remove PLCs from direct Internet exposure and place them behind secure gateways, firewalls, or VPNs.
     <br/>
     • Change default credentials and enforce strong, unique passwords for PLCs and associated OT systems.
     <br/>
     • Implement access control lists (ACLs) to restrict communications to authorized devices and expected sources.
     <br/>
     • Restrict remote access to OT environments and require secure authentication for authorized users.
     <br/>
     • Monitor PLC configurations and network activity for unauthorized changes, including unexpected modifications to IP addresses, passwords, or operating parameters.
     <br/>
     • Segment OT and IT networks to limit lateral movement following a compromise.
     <br/>
     • Review exposed PLCs and other Internet-facing OT assets and remove unnecessary public access.
     <br/>
     • Maintain offline backups of PLC configurations to support recovery if unauthorized changes or operational disruptions occur.
     <br/>
     <br/>
     The FBI specifically recommends removing PLCs from direct Internet exposure, using strong unique passwords, and implementing ACLs to restrict communications
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • FortiGuard Operational Technology Security Service: Provides specialized protection for OT/ICS environments, helping identify and protect against threats targeting industrial control systems, including PLCs and other critical OT assets.
     <a href="https://www.fortiguard.com/encyclopedia/otapp/10002574" rel="noopener noreferrer nofollow" target="_blank">
      OT App Detection | FortiGuard Labs
     </a>
     <br/>
     • FortiGuard IPS Service: Detects and blocks network-based attacks targeting exposed OT/ICS services and PLC infrastructure.
     <br/>
     • FortiGuard Web Filtering: Blocks access to known malicious infrastructure associated with threat activity.
     <br/>
     • FortiGuard Antivirus &amp; Behavior Detection: Detects malicious payloads that may be delivered following network compromise.
     <br/>
     • FortiGuard IOC Service: Identifies known indicators associated with malicious infrastructure and post-compromise activity.
     <br/>
     • FortiGuard Incident Response: Supports investigation, containment, and recovery following an OT/ICS compromise.
    </p>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6498</guid><pubDate>Fri, 28 Aug 2026 18:01:45 -0700</pubDate></item><item><title>Siemens S7 Series PLCs and other Internet-exposed PLC Attack</title><link>https://fortiguard.fortinet.com/threat-signal-report/6509</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Attack?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     U.S. cybersecurity agencies, including CISA, NSA, FBI, DOE, and EPA, have warned of an active cyber threat targeting Siemens S7 Series PLCs that are Internet-exposed, running outdated software, or otherwise inadequately protected.
     <br/>
     <br/>
     The advisory highlights activity involving reconnaissance and unauthorized interaction with PLCs, including scanning of Internet-accessible industrial systems. Successful access to PLCs could allow threat actors to modify industrial processes, disrupt operations, manipulate control logic, introduce safety hazards and cause physical damage.
     <br/>
     <br/>
     Organizations operating Siemens S7 Series PLCs should immediately assess Internet exposure, network segmentation, access controls, monitoring, and PLC-specific security configurations.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     1. Inventory Siemens S7 Series PLCs:
     <br/>
     • Identify all Siemens S7 Series PLCs within the environment.
     <br/>
     • Identify firmware versions and device details.
     <br/>
     • Determine which PLCs are reachable from untrusted or external networks.
     <br/>
     • Use FortiGuard Operational Technology Security Service (OTSS) for OT asset discovery and device identification.
     <br/>
     <br/>
     2. Verify Network Segmentation:
     <br/>
     • Ensure Siemens S7 PLCs are not directly accessible from the Internet.
     <br/>
     • Restrict access to S7 communications, including TCP/102, to authorized systems.
     <br/>
     • Segment OT networks from enterprise and corporate networks.
     <br/>
     • Use DMZ architectures where communication between IT and OT is required.
     <br/>
     • Restrict routing between untrusted networks and PLC environments.
     <br/>
     • Apply appropriate controls to historian and monitoring communications to limit unauthorized write access.
     <br/>
     <br/>
     FortiOS and FortiGate can enforce network segmentation, routing restrictions, and policy-based access controls, while OTSS provides OT-aware visibility and monitoring.
     <br/>
     <br/>
     3. Strengthen Access Controls:
     <br/>
     • Restrict PLC access to authorized engineering workstations and management systems.
     <br/>
     • Use network access policies rather than relying solely on PLC IP/MAC allowlisting.
     <br/>
     • Apply application controls to engineering workstations using FortiEDR.
     <br/>
     • Require MFA for remote access to OT environments using FortiPAM and/or FortiGate.
     <br/>
     • Minimize remote administrative access to PLCs and engineering systems.
     <br/>
     <br/>
     4. Enable Comprehensive OT Monitoring and Logging:
     <br/>
     Monitor for:
     <br/>
     • Unauthorized S7 connections to PLCs.
     <br/>
     • Unexpected S7 PUT/GET operations.
     <br/>
     • Unauthorized PLC configuration or program changes.
     <br/>
     • IP scanning and reconnaissance activity.
     <br/>
     • S7 protocol scanning and enumeration.
     <br/>
     • Unexpected communication with PLCs from enterprise or external networks.
     <br/>
     <br/>
     FortiGuard OTSS provides OT-aware visibility and monitoring, while FortiGate/FortiGuard IPS can detect and block network activity targeting S7 services and protocols, including S7 scanning and enumeration activity.
     <br/>
     <br/>
     5. Implement S7-Specific Hardening:
     <br/>
     • Restrict access to PLC web interfaces and disable unnecessary services where supported.
     <br/>
     • Disable unused protocols and services.
     <br/>
     • Limit S7 communications to required source and destination systems.
     <br/>
     • Review PLC security settings and engineering workstation configurations.
     <br/>
     • Validate PLC programs, configurations, firmware, and logic for unauthorized changes.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • FortiGuard Operational Technology Security Service (OTSS) – Provides OT asset discovery, device identification, protocol-aware monitoring, and security visibility for industrial environments, including Siemens S7 infrastructure.
     <a href="https://www.fortiguard.com/search?q=S7&amp;type=otsips&amp;sort=0" rel="noopener noreferrer nofollow" target="_blank">
      FortiGuard Labs
     </a>
     <br/>
     • FortiGate / FortiOS – Enforces network segmentation, access-control policies, routing restrictions, and controlled connectivity between enterprise, DMZ, and OT environments.
     <br/>
     • FortiGuard IPS – Detects and blocks network-based attacks, scanning, enumeration, and suspicious activity targeting industrial protocols and services, including Siemens S7 communications.
     <br/>
     • FortiEDR – Protects engineering workstations against malicious applications and unauthorized activity that could be used to compromise OT environments.
     <br/>
     • FortiPAM – Provides privileged access management and supports stronger controls, including MFA, for administrative and remote access to critical systems.
     <br/>
     • FortiGuard Network Detection and Response (NDR) – Provides additional network visibility and behavioral detection to identify anomalous activity within OT and IT environments.
     <br/>
     • FortiGuard Incident Response – Supports investigation, containment, and recovery following suspected compromise of PLCs or OT infrastructure.
    </p>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6509</guid><pubDate>Fri, 28 Aug 2026 18:01:36 -0700</pubDate></item><item><title>NGINX Heap-Based Buffer Overflow</title><link>https://fortiguard.fortinet.com/threat-signal-report/6508</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Vulnerability?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     FortiGuard Labs is tracking an exploitation risk associated with CVE-2026-42533, a heap-based buffer overflow vulnerability affecting NGINX Open Source and NGINX Plus. The flaw occurs when the map directive uses regex matching and capture variables in a specific configuration pattern. An unauthenticated remote attacker can send crafted HTTP requests that may crash the NGINX worker process, resulting in denial of service, and potentially achieve remote code execution when ASLR is disabled or bypassed.
     <br/>
     <br/>
     The vulnerability was publicly disclosed by F5 on July 15, 2026, with NGINX releasing fixed versions the same day.
    </p>
    <p>
     Fortinet has conducted an internal security review of products and services that use NGINX. Based on the current assessment, Fortinet products are not affected by CVE-2026-42533.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     Affected products:
     <br/>
     NGINX Open Source 0.9.6–1.30.3 and 1.31.0–1.31.2
     <br/>
     NGINX Plus R33–R36
     <br/>
     NGINX Plus R37 37.0.0.1–37.0.2.1
     <br/>
     NGINX Ingress Controller, NGINX Gateway Fabric, NGINX App Protect WAF, and other F5/NGINX products with affected bundled versions.
     <br/>
     <br/>
     Organizations should:
     <br/>
     • Upgrade NGINX Open Source to 1.30.4 or 1.31.3 or later, depending on the deployment branch.
     <br/>
     • Upgrade NGINX Plus to a fixed release, including R36 P7 or 37.0.3.1 where applicable.
     <br/>
     • Review NGINX configurations for map directives using regex captures and confirm whether vulnerable variable-reference patterns are present.
     <br/>
     • Prioritize Internet-facing NGINX deployments and reverse proxies.
     <br/>
     • Deploy WAF protections to detect and block malicious HTTP requests targeting vulnerable NGINX configurations while patching is underway.
     <br/>
     • Monitor NGINX worker-process crashes, abnormal HTTP requests, and other indicators of attempted exploitation.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • FortiGuard IPS Service: Detects and blocks network-based attacks targeting vulnerable NGINX assets.
     <a href="https://www.fortiguard.com/encyclopedia/ips/61761" rel="noopener noreferrer nofollow" target="_blank">
      Intrusion Prevention | FortiGuard Labs
     </a>
     <br/>
     • FortiWeb: Provides mitigation for CVE-2026-42533 through a custom signature and HTTP protocol constraint to help protect vulnerable NGINX deployments while patching is underway.
     <a href="https://community.fortinet.com/fortiweb-40/technical-tip-defending-against-2026-42533-with-fortiweb-229193" rel="noopener noreferrer nofollow" target="_blank">
      Technical Tip: Defending against 2026-42533 with FortiWeb | Community
     </a>
     <br/>
     • FortiGuard Vulnerability Management: Identifies vulnerable NGINX assets and helps prioritize remediation based on exposure and risk.
     <br/>
     • FortiGuard Incident Response Service: FortiGuard Incident Response Service assists organizations in investigating potential compromise, determining the scope of attacker activity, and supporting containment, remediation, and recovery efforts following exploitation.
    </p>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6508</guid><pubDate>Mon, 24 Aug 2026 20:31:08 -0700</pubDate></item><item><title>WordPress Core Unauthenticated RCE (WP2Shell)</title><link>https://fortiguard.fortinet.com/threat-signal-report/6492</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Attack?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack chain affecting WordPress Core. Unlike most WordPress attacks that rely on vulnerable plugins or themes, WP2Shell impacts the WordPress core application itself, allowing attackers to compromise default installations without requiring any plugins or authentication. Public proof-of-concept (PoC) exploits are widely available, and active exploitation has been reported shortly after technical details were disclosed.
     <br/>
     <br/>
     Successful exploitation may allow attackers to:
     <br/>
     • Execute arbitrary code on the web server.
     <br/>
     • Create unauthorized administrator accounts.
     <br/>
     • Deploy web shells or persistent backdoors.
     <br/>
     • Steal sensitive website and database contents.
     <br/>
     • Install malware or ransomware.
     <br/>
     • Use compromised servers for further attacks.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     Affected Versions:
     <br/>
     WordPress 6.9.0 – 6.9.4
     <br/>
     WordPress 7.0.0 – 7.0.1
     <br/>
     WordPress 7.1 Beta
     <br/>
     <br/>
     Organizations should immediately:
     <br/>
     • Upgrade WordPress to the latest patched release (6.9.5, 7.0.2, or later).
     <br/>
     • Restrict unnecessary exposure of WordPress administrative interfaces.
     <br/>
     • Monitor for unauthorized administrator account creation.
     <br/>
     • Review web server logs for suspicious REST API batch endpoint requests.
     <br/>
     • Scan for web shells and other indicators of compromise.
     <br/>
     • Apply network protections capable of detecting SQL injection and exploitation attempts.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <ul>
     <li>
      <p>
       FortiGuard IPS Service - Detects and blocks exploitation attempts targeting the WP2Shell vulnerability chain.
       <a href="https://www.fortiguard.com/encyclopedia/ips/61474" rel="noopener noreferrer nofollow" target="_blank">
        Intrusion Prevention | FortiGuard Labs
       </a>
      </p>
     </li>
     <li>
      <p>
       FortiGuard Web Application Firewall (WAF) - Protects against SQL injection and malicious REST API requests.
       <a href="https://www.fortiguard.com/encyclopedia/fwb/1090502560" rel="noopener noreferrer nofollow" target="_blank">
        Web Application Security | FortiGuard Labs
       </a>
      </p>
     </li>
     <li>
      <p>
       FortiGuard Web Filtering - Blocks access to known malicious infrastructure.
      </p>
     </li>
     <li>
      <p>
       FortiGuard Antivirus &amp; Behavior Detection - Detects malware and web shells deployed after successful exploitation.
      </p>
     </li>
     <li>
      <p>
       FortiGuard IOC Service - Identifies indicators associated with compromised WordPress servers.
      </p>
     </li>
     <li>
      <p>
       FortiGuard Incident Response - Assists with investigation, containment, and recovery following compromise.
      </p>
     </li>
    </ul>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6492</guid><pubDate>Wed, 29 Jul 2026 21:33:51 -0700</pubDate></item><item><title>PTC Windchill &amp; FlexPLM RCE</title><link>https://fortiguard.fortinet.com/threat-signal-report/6491</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Attack?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Management (PLM) systems to deploy web shells, steal intellectual property, and carry out double-extortion ransomware attacks.
    </p>
    <p>
     The campaign chains a pre-authentication information disclosure vulnerability in the FlexPLM endpoint with CVE-2026-12569 to achieve unauthenticated remote code execution. Following compromise, attackers deploy JSP web shells, perform file system discovery, exfiltrate sensitive information, and ultimately issue ransom demands to affected organizations.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     Organizations using PTC Windchill or FlexPLM should:
     <br/>
     • Apply the latest vendor security updates immediately.
     <br/>
     • Verify whether systems are internet accessible and restrict external exposure where possible.
     <br/>
     • Hunt for JSP web shells within the /Windchill/login/ directory.
     <br/>
     • Review logs for suspicious requests targeting Windchill login endpoints.
     <br/>
     • Rotate credentials and perform a full compromise assessment if exploitation is suspected.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • FortiGuard IPS Service helps detect and block exploitation attempts targeting vulnerable PTC Windchill PDMlink and FlexPLM servers before attackers can gain remote code execution.
     <a href="https://www.fortiguard.com/encyclopedia/ips/61212" rel="noopener noreferrer nofollow" target="_blank">
      Intrusion Prevention | FortiGuard Labs
     </a>
     <br/>
     • FortiGuard Antivirus &amp; Behavior Detection Service identifies and blocks malicious payloads and suspicious post-exploitation behavior associated with Cl0p intrusion activity.
     <br/>
     • FortiGuard Web Filtering Service prevents access to known malicious domains, command-and-control (C2) infrastructure, and phishing sites used during the attack lifecycle.
     <br/>
     • FortiGuard IOC Service provides up-to-date indicators of compromise (IOCs), enabling security teams to identify affected systems, detect attacker activity, and accelerate threat hunting.
     <br/>
     • FortiGuard Incident Response Service assists organizations with incident investigation, containment, forensic analysis, eradication of attacker persistence, and recovery following a confirmed compromise.
    </p>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6491</guid><pubDate>Tue, 28 Jul 2026 16:57:05 -0700</pubDate></item><item><title>Joomla SP Page Builder RCE</title><link>https://fortiguard.fortinet.com/threat-signal-report/6489</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Vulnerability?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     FortiGuard telemetry shows continued exploitation attempts targeting vulnerable Joomla SP Page Builder installations. CVE-2026-48908 is a critical unauthenticated remote code execution (RCE) vulnerability affecting the SP Page Builder extension for Joomla. The flaw allows attackers to upload arbitrary PHP files through the custom icon upload functionality without authentication, potentially enabling remote code execution and full server compromise.
     <br/>
     <br/>
     Public proof-of-concept (PoC) exploit code is available, and active exploitation has been observed. The sustained increase in weekly exploitation activity indicates ongoing automated scanning campaigns targeting Internet-facing Joomla servers, highlighting the need for immediate patching and monitoring of vulnerable deployments.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • Upgrade SP Page Builder to version 6.6.2 or later.
     <br/>
     • Restrict public access to Joomla administrative interfaces.
     <br/>
     • Prevent PHP execution from upload/media directories.
     <br/>
     • Monitor for unexpected PHP files and newly created administrator accounts.
     <br/>
     • Review web server logs for suspicious POST requests targeting the SP Page Builder upload endpoint.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • FortiGuard Intrusion Prevention System (IPS) protects against exploitation attempts targeting vulnerable SP Page Builder deployments.
     <a href="https://www.fortiguard.com/encyclopedia/ips/61172" rel="noopener noreferrer nofollow" target="_blank">
      Intrusion Prevention | FortiGuard Labs
     </a>
     <br/>
     • FortiGuard Web Filtering blocks access to known malicious domains, command-and-control infrastructure, and payload hosting locations associated with post-exploitation activity.
     <br/>
     • FortiGuard Antivirus detects and blocks malicious payloads, web shells, backdoors, and other malware that attackers may deploy after successfully exploiting vulnerable Joomla installations.
     <br/>
     • FortiEDR detects suspicious post-exploitation activities, including unauthorized command execution, web shell execution, persistence attempts, credential theft, and lateral movement from compromised Joomla servers.
     <br/>
     • FortiGuard Incident Response Service helps organizations investigate suspected compromises, identify attacker activity, determine the scope of impact, and support containment, remediation, and recovery efforts following exploitation.
    </p>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6489</guid><pubDate>Fri, 17 Jul 2026 02:21:09 -0700</pubDate></item><item><title>Ubiquiti UniFi OS RCE</title><link>https://fortiguard.fortinet.com/threat-signal-report/6475</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Vulnerability?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     Multiple critical vulnerabilities affecting Ubiquiti UniFi OS can be chained together to achieve unauthenticated remote code execution (RCE) with root privileges. The vulnerabilities include CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which together bypass authentication, access protected resources, and execute arbitrary operating system commands.
     <br/>
     <br/>
     The vulnerabilities impact UniFi OS deployments used to manage enterprise networking infrastructure, including gateways, network controllers, video surveillance, and access control systems. Researchers have publicly demonstrated the exploit chain, and the vulnerabilities have been confirmed as actively exploited in the wild. Organizations should immediately upgrade affected systems and restrict management interfaces from Internet exposure.
     <br/>
     <br/>
     Successful exploitation could allow attackers to:
     <br/>
     • Obtain root-level remote code execution.
     <br/>
     • Completely compromise UniFi OS devices.
     <br/>
     • Steal administrative credentials and configuration data.
     <br/>
     • Modify firewall, VPN, and network settings.
     <br/>
     • Deploy malware or ransomware.
     <br/>
     • Pivot into internal enterprise networks.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     Organizations should:
     <br/>
     <br/>
     • Immediately upgrade to the latest patched UniFi OS release.
     <br/>
     • Restrict UniFi management interfaces to trusted administrative networks.
     <br/>
     • Avoid exposing UniFi OS management portals directly to the Internet.
     <br/>
     • Monitor logs for suspicious authentication attempts and command execution.
     <br/>
     • Review systems for indicators of compromise if Internet exposure existed prior to patching.
     <br/>
     • Apply network segmentation and least-privilege administrative access.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • FortiGuard Intrusion Prevention System (IPS) protects against exploit attempts.
     <a href="https://www.fortiguard.com/encyclopedia/ips/61199" rel="noopener noreferrer nofollow" target="_blank">
      Intrusion Prevention | FortiGuard Labs
     </a>
     <br/>
     • FortiGuard Web Filtering blocks access to known malicious infrastructure used to host payloads or support post-exploitation command-and-control activity.
     <br/>
     • FortiGuard Antivirus detects and blocks malware payloads, web shells, and other malicious files delivered following successful exploitation.
     <br/>
     • FortiEDR detects suspicious post-exploitation behavior, including unauthorized command execution, persistence mechanisms, privilege abuse, and lateral movement originating from compromised systems.
     <br/>
     • FortiGuard Incident Response Service assists organizations in investigating potential compromise, determining the scope of attacker activity, and supporting containment, remediation, and recovery efforts following exploitation.
    </p>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6475</guid><pubDate>Wed, 08 Jul 2026 18:20:11 -0700</pubDate></item><item><title>Ivanti Sentry Pre-Authentication RCE</title><link>https://fortiguard.fortinet.com/threat-signal-report/6472</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Vulnerability?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical details and proof-of-concept (PoC) exploit code.
     <br/>
     <br/>
     CVE-2026-10520 is a critical vulnerability affecting Ivanti Sentry that allows remote, unauthenticated attackers to execute arbitrary operating system commands with root privileges. The flaw stems from improper handling of internal configuration commands exposed through an externally accessible API, enabling complete device compromise without valid credentials.
     <br/>
     <br/>
     Shortly after disclosure, watchTowr published a detailed technical analysis and public PoC, significantly lowering the barrier to exploitation and increasing the likelihood of opportunistic attacks.
     <br/>
     <br/>
     Ivanti Sentry is an enterprise mobile gateway that provides secure access to corporate email, applications, and content for managed mobile devices. Organizations with internet-exposed Ivanti Sentry appliances should prioritize patching immediately, as attackers are actively attempting to exploit vulnerable systems.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     Affected:
     <br/>
     Ivanti Sentry 10.5.1 and earlier
     <br/>
     Ivanti Sentry 10.6.1 and earlier
     <br/>
     Ivanti Sentry 10.7.0 and earlier
     <br/>
     <br/>
     Fixed:
     <br/>
     10.5.2
     <br/>
     10.6.2
     <br/>
     10.7.1
     <br/>
     <br/>
     Recommended Actions
     <br/>
     • Immediately upgrade to Ivanti Sentry 10.5.2, 10.6.2, or 10.7.1.
     <br/>
     • Assume internet-exposed, unpatched appliances may already be compromised.
     <br/>
     • Review administrative accounts for unauthorized additions.
     <br/>
     • Search for web shells, persistence mechanisms, and suspicious root-level processes.
     <br/>
     • Rotate credentials and invalidate tokens if compromise is suspected.
     <br/>
     • Monitor for exploitation attempts and anomalous outbound connections.
     <br/>
     • Enable IPS protections and virtual patching while emergency updates are being deployed.
     <br/>
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • FortiGuard IPS protects against exploit attempts targeting vulnerable Ivanti Sentry appliances.
     <a href="https://www.fortiguard.com/encyclopedia/ips/61065" rel="noopener noreferrer nofollow" target="_blank">
      Intrusion Prevention | FortiGuard Labs
     </a>
     <br/>
     • FortiGuard Web Filtering blocks access to known malicious infrastructure used to host payloads or support post-exploitation command-and-control activity.
     <br/>
     • FortiGuard AntiVirus detects and blocks malware payloads, web shells, and other malicious files delivered following successful exploitation.
     <br/>
     • FortiEDR detects suspicious post-exploitation behavior, including unauthorized command execution, persistence mechanisms, privilege abuse, and lateral movement originating from compromised systems.
     <br/>
     • FortiGuard Incident Response Service assists organizations in investigating potential compromise, determining the scope of attacker activity, and supporting containment, remediation, and recovery efforts following exploitation.
    </p>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6472</guid><pubDate>Fri, 03 Jul 2026 17:53:55 -0700</pubDate></item><item><title>Splunk Enterprise Authentication Bypass Vulnerability</title><link>https://fortiguard.fortinet.com/threat-signal-report/6470</link><description><![CDATA[<table class="MsoNormalTable">
 <colgroup>
  <col/>
  <col/>
 </colgroup>
 <tbody>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the Attack?
    </p>
   </td>
   <td class="ts-desc" colspan="1" rowspan="1">
    <p>
     A critical authentication bypass vulnerability, CVE-2026-20253 (CVSS 9.8), affects Splunk Enterprise versions 10.0.x and 10.2.x. The flaw stems from missing authentication on a PostgreSQL sidecar service endpoint, allowing an unauthenticated attacker to create or truncate arbitrary files on a vulnerable server.
     <br/>
     <br/>
     Security researchers have demonstrated that the vulnerability can be leveraged toward pre-authentication remote code execution (RCE) under certain conditions, and active exploitation has been confirmed. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, making it a high-priority patching target for organizations running exposed Splunk Enterprise instances.
     <br/>
     <br/>
     An attacker who successfully exploits CVE-2026-20253 may be able to:
     <br/>
     • Create or truncate arbitrary files on the target server.
     <br/>
     • Bypass authentication protections.
     <br/>
     • Potentially achieve pre-authentication remote code execution.
     <br/>
     • Disrupt Splunk services.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What is the recommended Mitigation?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     Affected:
     <br/>
     Splunk Enterprise 10.2 prior to 10.2.4
     <br/>
     Splunk Enterprise 10.0 prior to 10.0.7
     <br/>
     <br/>
     Upgrade to:
     <br/>
     Splunk Enterprise 10.2.4 or later
     <br/>
     Splunk Enterprise 10.0.7 or later
     <br/>
     <br/>
     If immediate patching is not possible:
     <br/>
     • Disable the PostgreSQL sidecar service as recommended by Splunk.
     <br/>
     • Restrict network access to Splunk management interfaces.
     <br/>
     • Monitor for unexpected file creation or service behavior.
     <br/>
     • Review logs for suspicious unauthenticated access attempts.
    </p>
   </td>
  </tr>
  <tr>
   <td colspan="1" rowspan="1">
    <p>
     What FortiGuard Coverage is available?
    </p>
   </td>
   <td colspan="1" rowspan="1">
    <p>
     • FortiGuard IPS provides protection against exploit attempts targeting vulnerable services.
     <br/>
     • FortiGuard Web Filtering blocks access to known malicious infrastructure used during exploitation.
     <br/>
     • FortiGuard AntiVirus detects and blocks malware payloads delivered following successful exploitation.
     <br/>
     • FortiEDR detects suspicious post-exploitation behavior, including unauthorized file modifications and persistence techniques.
     <br/>
     • FortiGuard Incident Response Service assists organizations in investigating and determining the scope of compromise, and supporting remediation efforts following exploitation.
     <br/>
    </p>
   </td>
  </tr>
 </tbody>
</table>
]]></description><guid isPermaLink="true">https://fortiguard.fortinet.com/threat-signal-report/6470</guid><pubDate>Mon, 29 Jun 2026 21:52:21 -0700</pubDate></item></channel></rss>