Fortinet has confirmed a critical vulnerability in FortiManager which is being tracked as CVE-2024-47575, and has a CVSS score 9.8 which is basically the worst score you can get, is being actively exploited. Mandiant has details about what this vulnerability is and how it is exploited.
But that’s not the bad part.
Apparently according to Bleeping Computer, this was disclosed to customers a week ago and….:
The company privately warned FortiManager customers about the flaw starting October 13th in advanced notification emails seen by BleepingComputer that contained steps to mitigate the flaw until a security update was released.
However, news of the vulnerability began leaking online throughout the week by customers on Reddit and by cybersecurity researcher Kevin Beaumont on Mastodon, who calls this flaw “FortiJump.”
Fortinet device admins have also shared that this flaw has been exploited for a while, with a customer reporting being attacked weeks before the notifications were sent to customers.
“We got breached on this one weeks before it hit “advance notifications” – 0-day I guess,” reads a now-deleted comment on Reddit.
That’s not good at all. Patches to FotiManager are either here or are coming. And I highly recommend that you install those patches ASAP. Having said that, Fortinet is going to have to answer some hard questions about how they handled this because their response seems a bit suspect to me.




Cyware, ECS enter design partnership to strengthen Gov’t & CI cybersecurity
Posted in Commentary with tags Cyware on October 24, 2024 by itnerdCyware, the leading provider of threat intelligence management, low-code/no-code automation, and cyber fusion solutions, and ECS, a leader in advanced technology solutions for U.S. public sector customers, including defense and intelligence organizations, today announce their design partnership which will serve to enhance Cyware’s Intel Exchange product enabling government entities to improve their security posture. This partnership aims to leverage ECS’s deep public-sector knowledge and cybersecurity expertise to tailor Cyware’s Intel Exchange to address the unique needs of government entities, with a focus on strengthening collective defense and securing the nation’s critical infrastructure.
To address the security challenges that impact federal entities, Cyware and ECS are working together to:
The full range of enhanced capabilities for Intel Exchange are expected to be unveiled for the public sector in early November 2024. Cyware and ECS remain committed to supporting federal agencies through innovative and tailored cybersecurity solutions that promote collective defense and protect the nation’s most critical infrastructure.
Leave a comment »