Archive for Fortra

2026 Cyber Predictions From Forta

Posted in Commentary with tags on November 17, 2025 by itnerd

The Fortra Intelligence and Research Experts (FIRE) team have released 2026 predictions that uncover the darker side of AI and the next evolution of cyber defense.

John Grancarich, Chief Strategy Officer

Brand protection will expand the attack surface. The attack surface as it stands now includes an organization’s brand, its executives and its online reputation. By 2026, protecting trust beyond the network – across the open web, social platforms and dark web – will become as critical as protecting the network itself.

Tyler Reguly, Associate Director, Security R&D

Companies that over invest in AI and put emphasis on AI over humans will start to struggle. As everyone likes to say, ‘Today, AI is the worst it will ever be.” With that said, AI isn’t great. It is costly and limited in capabilities. While some tasks are performed amazingly, others demonstrate the real weakness in reliance on AI. AI is a tool and should be treated as such. It can increase productivity, but it can’t be productive on its own. That requires human expertise and companies that realize that early and retain their experts will prosper over those that adopt AI-only strategies. 

Josh Taylor, Lead Security Analyst, Fortra

Attacks on critical infrastructure will accelerate. Nation-state and criminal actors will target energy, healthcare, and transportation systems with cyber-physical impacts, turning outages and disruptions into strategic weapons. Enterprises in these sectors must treat cybersecurity as a safety imperative and plan for worst-case operational scenarios.

November Patch Tuesday Commentary From Fortra

Posted in Commentary with tags on November 12, 2025 by itnerd

Tyler Reguly, Associate Director, Security R&D, Fortra

Microsoft seems to have decided that the past few months have given us all the entertainment that we needed and toned things down a little this month. We do have one CVE that has seen active exploitation (CVE-2025-62215) and 6 CVEs that Microsoft has assigned a severity level of Critical (CVE-2025-60724, CVE-2025-62214, CVE-2025-62199, CVE-2025-60716, CVE-2025-60724, CVE-2025-30398). This set includes the single CVE, CVE-2025-60724, to also earn a critical severity on the CVSS scale with a score of 9.8. That 9.8 is something that will likely get a lot of discussion.

One of the things that makes CVE-2025-60724 interesting is a remark that Microsoft made in the FAQ, “In the worst-case scenario, an attacker could trigger this vulnerability on web services by uploading documents containing a specially crafted metafile (AV:N) without user interaction.” This is where I tend to find fault with the way Microsoft handles these vulnerabilities. We have traditional Windows cumulative updates, but a very non-standard attack vector – file upload. There are plenty of unknowns with this one and a lot of questions that we could ask… “Does the technology matter? The backend language processing the metafile? The web server selection?” Microsoft isn’t exactly giving me a lot of confidence that I could mitigate or reduce my risk if patching isn’t immediately possible.

If I’m a CISO, then CVE-2025-60724 has me worried this month. We have a vulnerability that Microsoft and CVSS agree is critical and an attack vector that requires no user interaction and no privileges, just the ability to upload a file. We know nothing about the file type, the technologies that are impacted (other than GDI+ in the title), or the services impacted. Do I need to worry about my SharePoint infrastructure? What about third-party software – my wiki or my bug tracker? This is definitely one that feels a little spooky without a lot of extra details being provided.

While not directly related to today’s patch drop, I wanted to call attention to the additional documentation (via blog post: https://www.microsoft.com/en-us/msrc/blog/2025/10/understanding-cve-2025-55315) that Microsoft published related to CVE-2025-55315. This is fantastic additional context around the vulnerability and the risks involved. This is the type of documentation that we should see for every critical or actively exploited vulnerability that Microsoft patches. If you are a CISO or in communication with a Microsoft TAM, you should reach out and let them know that this is an improvement to their communication and that releasing content like this for more vulnerabilities and in a more timely fashion would be hugely beneficial to the security community.

Guest Post: Cybersecurity Tips for the Holidays From Fortra

Posted in Commentary with tags on November 7, 2025 by itnerd

By John Wilson, Senior Fellow, Threat Research at Fortra

1. Holiday Job Scams  

The holiday season often brings a surge in temporary and remote job listings — and scammers are taking advantage of those looking for work. They pose as recruiters from well-known companies, send fake job offers to collect personal information, and demand upfront payments for “training” or “equipment.” They are even incorporating AI, making scams increasingly difficult to identify. 

Before accepting any offer, verify the opportunity directly through the company’s official website or HR department. Legitimate employers will never ask for money or sensitive data during the hiring process. A few red flags: No company is going to hire you without an interview no matter how qualified you may be for the position. Scam job offerings almost always mention a minimum age requirement. This is so they have an excuse to ask for a photo of your ID. Finally, look to see who sent the message and who it was sent to. A lot of scam texts and emails will come from a strange phone number or email address, and many scammers will send messages to numerous recipients at the same time. 

2. Gift Card Scams 

The use of gift cards during the holiday season ramps up, and so does the attackers’ exploitation of them. Attackers can send their victims emails claiming they’ve won a gift card or received a gift. These may even be customized with AI generated images and tend to impersonate popular retailer brands to increase the authenticity of the fake gift card. But to claim it, they’ll say you must give your personal information or pay a shipping fee first.  

If you receive a message like this, remember that legitimate companies will not ask you for payment to receive a gift card.  

3. Fake Shopping Websites and Ads 

Fake websites, such as phishing sites or phishing, remain a top threat for consumers conducting their holiday shopping online. Cybercriminals often create ‘eCommerce’ websites optimized for search engines and offer goods at below market prices to entice consumers into making a purchase. These sites may even be shared on social media platforms and circulate around as fake enticing ads to lure as many victims as possible.  

When you hand over your payment details by shopping on these sites, the hackers record them and use them to commit identity fraud and fraudulent purchases later. 

4. Always Use Secure Payment Methods 

Never use a debit card online and avoid other payment methods that don’t provide adequate fraud protection when conducting your holiday online shopping. Credit cards tend to be a safer option against fraud, and services such as Apple Pay or Google Pay are generally more secure than entering your card information directly. Some credit card issuers enable you to create virtual card numbers to use on a single website. This is helpful because the card number can’t be used by a scammer to clone your credit card or to purchase from some other website. 

This could protect you from fraud, impersonation, and reduce the likelihood of an attacker compromising your bank accounts.  

5. Travel Scams 

The holiday season is the season of travel, and scammers are always on the lookout for ways to take advantage of these vacation plans. Victims can receive phishing emails offering discounted travel deals and offers that impersonate legitimate online travel service providers. Booking travel plans through these fake malicious sites can compromise your sensitive personal information and even lead to financial losses.  

Always verify the legitimacy of websites by navigating to the service provider’s website directly instead of using suspicious links embedded in emails, use secure payment methods to protect your personal information, and remember – if a deal is too good to be true, it likely is.  

Fortra Threat Hunts Reveal Emerging MITRE Attack Techniques 

Posted in Commentary with tags on October 30, 2025 by itnerd

Fortra Intelligence and Research Experts (FIRE) initiated more than 2,700 threat hunts across customer environments in August 2025. Using the MITRE ATT&CK framework, FIRE has identified and is sharing the top tactics and the most common techniques used in these attacks.

Identifying these evolving attacker behaviors is a key component to helping security teams strengthen defenses and disrupt threats before they escalate, in addition to understanding how threat actors are refining social engineering and cloud exploitation techniques.

You can read the research here: Top Threat Hunting Metrics & Outcomes | Fortra

Fortra Launches DSPM Solution to Protect Data From Endpoint to Cloud  

Posted in Commentary with tags on October 29, 2025 by itnerd

Fortra announced today the launch of its new Data Security Posture Management (DSPM) solution to enable organizations to discover, classify, and protect sensitive data across their hybrid cloud. Fortra DSPM expands the company’s comprehensive security portfolio by addressing one of the most critical challenges facing modern enterprises: maintaining visibility and control over data in increasingly complex, distributed environments. 

As organizations increasingly embrace hybrid cloud architectures, sensitive data continues to proliferate across countless shadow repositories, applications, and environments. The modern threat landscape demands that businesses not only know where their critical data resides, but also understand how it’s being accessed, used, and protected. Traditional data protection approaches fall short in today’s dynamic threat environments, creating dangerous blind spots that cybercriminals are quick to exploit. 

Fortra DSPM delivers automated data discovery across on-premises, cloud, and hybrid environments, intelligent classification of sensitive information, and continuous monitoring of data security posture. By providing real-time insights into data risks and compliance gaps, the solution enables security teams to proactively address vulnerabilities before they can be exploited.  

The DSPM solution integrates seamlessly with Fortra’s existing security portfolio, providing customers with a unified approach to protecting their infrastructure and data assets. 

 

Fortra Tracks Fivefold Increase in Brokerage Account Attacks

Posted in Commentary with tags on October 21, 2025 by itnerd

Fortra Intelligence and Research Experts (FIRE) have uncovered a fivefold increase in attacks targeting brokerage accounts year-over-year, with activity accelerating sharply in mid-2025. The campaigns demonstrate content patterns resembling the Chinese Phishing-as-a-Service group known as the “Smishing Triad,” use deceptive text messages to steal credentials, and intercept authentication codes. Once inside, attackers execute “ramp-and-dump” stock manipulation schemes while leaving almost no digital trace. 

You can read the report here: https://www.fortra.com/blog/fortra-tracks-fivefold-increase-brokerage-attacks-yoy

October Patch Tuesday Commentary From Fortra

Posted in Commentary with tags on October 14, 2025 by itnerd

By Tyler Reguly, Associate Director, Security R&D, Fortra

Today is a record setting day, one that should likely concern everyone in a few different ways. Today, Microsoft addressed, via direct and third-party CVE assignments, 196 CVEs. Since Microsoft moved away from security bulletins and toward security guidance in 2017, the record CVEs in a single month was 161 in January of this year. Today, however, Microsoft beat that record with a more than 20% increase.

Why should everyone be concerned? First, that is a lot of vulnerabilities to address and there’s definitely a few oddball issues this month that we don’t normally see. Today, for example, I learned about a new OS called IGEL OS. According to CVE-2025-47827, this vulnerability allows for a Secure Boot bypass. Similarly, there’s a vulnerability in the Trusted Computing Groups TPM2.0 reference implementation defined by CVE-2025-2884, which could lead to information disclosure. Not only are these issues we don’t normally see in a Patch Tuesday drop, but they are also issues that were disclosed months ago. The IGEL OS issue was disclosed in May, while the TPM2.0 issue was disclosed in June. Yet, Microsoft is just getting out patches for these issues now. If you’re a CISO, you might want your teams to ask your Microsoft TAMS why it took so long to get out updates.

One of the updates that I find more interesting this month is the fix for a set of privilege escalation vulnerabilities in the Agere Modem Driver that ships with Windows. These attacks, one of which has already seen active exploitation, can work even if the modem is not being used and will elevate the attacker’s access to administrator privileges. The fix, however, caught my attention because Microsoft is simply removing the driver, ltmdm64.sys, from the system. This driver removal addresses both CVE-2025-24990 and CVE-2025-24052.

CISOs this month may want to ask their teams if they are using Azure’s Confidential Computing (ACC) AMD-based clusters, due to the AMD processor vulnerability assigned CVE-2025-0033. Updates for this are currently in development, so there is no resolution process available right now. Instead, customers need to monitor their Azure Service Health Alerts to watch for notifications letting them know that they need to remove their ACC resources. If your teams are using ACC, you’ll want to check in regularly to ensure that they are paying attention for that reboot notification, so that you will ultimately know when this publicly disclosed vulnerability is resolved.

CISOs may also want to question their Microsoft contacts on the three Copilot vulnerabilities that were resolved this month. This is a time when an executive summary would be very useful, but unfortunately Microsoft did not include one for any of these three issues. Instead, all we know is that there were three spoofing issues, two within M365 Copilot Business Chat (CVE-2025-59286 and CVE-2025-59272) and one within M365 Word Copilot (CVE-2025-59252). I would want to ask three questions:

  1. What was the issue?
  2. What were the risks associated by the issue?
  3. Are there any ways that I can tell if my organization was impacted by the issue?

Unfortunately, Microsoft does not address this and simply lets us know that they have fully mitigated the issue and that there is no action that we need to take. With all the implementations of AI within organizations, I would think that CISOs would like a little more than, “There was a risk, we fixed it,” if they want to sleep better at night.

Fortra Uncovers New, AI-Powered Phishing Campaign Exploiting ActiveCampaign

Posted in Commentary with tags on September 18, 2025 by itnerd

Fortra Intelligence and Research Experts (FIRE) have discovered a large-scale phishing campaign exploiting ActiveCampaign to mass-produce AI-generated impersonation sites promoting Small Business Administration loans.

These attacks are harvesting detailed business and financial data presumed to fuel future spear-phishing campaigns. 

You can read more here: https://www.fortra.com/blog/attackers-exploit-activecampaign-deliver-thousands-ai-generated-sba-phish

September Patch Tuesday Commentary From Fortra

Posted in Commentary with tags on September 9, 2025 by itnerd

Tyler Reguly, Associate Director, Security R&D, Fortra

Today, we have to start with the CVE that made me do a double take. A CVE that I feel should be rejected by MITRE – CVE-2025-55234. We know that relay attacks are possible against SMB and we know that there are hardening mechanisms available to assist with this. So, why is Microsoft releasing a CVE where they state, “Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks.” (https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-55234) 

As far as I’m concerned, Microsoft told us they have assigned a CVE not because of a vulnerability but to raise awareness to new auditing capabilities that they’ve added to assist with protective measures. If that is the case, that is a misuse of the CVE system. If that is not the case, then Microsoft needs to provide clarification very quickly.

This month there is a single CVE with a CVSS score in the critical range, CVE-2025-55232 (https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-55232), a vulnerability in the Microsoft High Performance Compute (HPC) Pack that could allow unauthorized attackers to execute code over the network. That makes this a CVSS 9.8 vulnerability and one that people need to pay attention to. Microsoft has provided mitigation steps for those that cannot update immediately. This is important as the update for HPC Pack 2016 is to migrate to HPC Pack 2019 as there is no fix for HPC Pack 2016. Thankfully, Microsoft has labeled this as exploitation less likely with a severity of important, but it is still something that you’ll want to pay attention to if you have the High Performance Compute Pack deployed in your environment.

While Microsoft has identified 11 vulnerabilities as critical this month, only one of those is identified as exploitation more likely. A vulnerability in NTLM that could allow an authorized attacker to gain SYSTEM level privileges via a network-based attack. This is what you’ll want to pay attention to until you have patches deployed. Since this is a privilege escalation for an authenticated user, this is one of those, “the call is coming from inside the house” type situations and a great way for attackers to potentially move laterally in your network.

For CSOs paying attention this month, I would have a couple of questions that I’d ask my team to take back to my Microsoft reps.

First, are they confident that there was no exploitation or disclosure related to CVE-2025-55241(https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-55241), a vulnerability in Azure Entra that allowed for privilege elevation without the need for privileges… something I would typically think of as code execution rather than privilege escalation. This is a no customer action required vulnerability and has already been resolved by Microsoft, but knowing more about the scenario and having a guarantee that there was no past exploitation would be important to me.

Second, I would want to know more about CVE-2025-55234 and whether there truly is a vulnerability associated with it. If this is a vendor using a CVE simply to add a feature, that is something that CSOs everywhere need to push back against. There are enough legitimate CVEs being issued, that we shouldn’t have to worry about CVEs without new vulnerabilities. This just adds complexity to an already complex situation.

The State of Email Trust: Global DMARC Adoption Trends in Q2 2025

Posted in Commentary with tags on August 29, 2025 by itnerd

By John Wilson, Senior Fellow, Threat Research, Fortra

In the sprawling digital ecosystem of the modern web, trust hinges on invisible scaffolding: DNS configurations, registrar records, and cryptographic signaling that determines whether your inbox will deliver truth or treachery. With phishing, spoofing, and business email compromise continuing to exploit lapses in email authentication, one question looms large: Just how secure are the world’s most-visited domains? 

Armed with DNS records (MX, SPF, DMARC) and whois metadata from the top 10 million domains on the internet, this analysis offers one of the most expansive snapshots of global email hygiene to date. From configuration trends to systemic weak points, we peel back the layers of digital trust to reveal what’s been hiding in plain sight. 

The findings? At once expected and alarming. While many domains have embraced modern security standards, millions remain vulnerable — inviting attackers to impersonate, manipulate, and deceive. By analyzing registrar behavior, domain age, and adoption patterns, we uncover which corners of the internet are actively fortifying their defenses and which have left the door ajar. 

Sender Policy Framework (SPF): Adoption and Pitfalls in the Wild

SPF serves as the internet’s first line of defense against email spoofing, specifying which IP addresses are authorized to send mail on behalf of a domain. But while it’s foundational to email authentication, its real-world implementation varies wildly across the web’s most popular domains.

SPF Adoption at a Glance

Out of the 10 million domains analyzed: 

  • 3,666,641 (36.7%) published a syntactically valid SPF record
  • 140,843 (1.4%) published an SPF record with syntax errors or excessive DNS lookups
  • 6,192,516 (61.9%) had no SPF record at all 

This means that 63.3% of the 10 million most popular domains on the internet remain vulnerable to unauthorized sending and/or delivery issues. 

Common Misconfigurations

Among the domains with SPF records:

  • 110,732 (1.1%) exceeded the 10-DNS-lookup limit, rendering SPF evaluations unreliable. 
  • 4,479 (0.045%) used the `+all` mechanism (i.e., allow all), effectively nullifying the purpose of SPF. Worse, these domains open the door for cybercriminals to hijack the trust inherent in these domains to send phishing links, malware-laden messages, and launch social engineering attacks. Two particularly notable examples were ubuntu.com and civilservice.gov.uk. Imagine how easy it would be to lure UK citizens interested in civil service jobs with an authenticated message from careers@civilservice.gov.uk. Or consider the message below, which I sent to myself using nothing more than telnet: <Image Redacted for Email>
  • 2,632 misspelled the ip4: mechanism either by omitting the “4” or by inserting a “v”. 

DMARC: Visibility, Policy, and Gaps

DMARC builds upon SPF and DKIM to offer domain owners the ability to define how unauthenticated messages should be handled — and to receive reporting data on abuse attempts. It’s a vital control against phishing and brand impersonation, yet widespread adoption remains elusive. 
 

DMARC Adoption Snapshot

From the dataset of 10 million domains:

  • 1,816,866 (18.2%) had a valid DMARC record
  • 1,061,585 (10.6%) had a record with a `p=none` policy, offering visibility but no enforcement
  • 755,281(7.6%) implemented enforcement policies (`p=quarantine` or `p=reject`)
  • 20,384 (0.2%) had malformed or incomplete DMARC entries
  • 8,162,614 (81.6%) lacked a DMARC record entirely 

Despite growing awareness, only 388,096 (3.9%) of the internet’s 10 million most popular domains enforce a reject policy including on subdomains, exposing the remaining domains to spoofing risks even when SPF and DKIM are configured.

Common DMARC Configuration Issues

For domains that published a DMARC record, the most common error was the omission of the mailto: before the rua and/or ruf reporting addresses. The second most common error was misplacement of the policy p= tag, which must occur immediately after the v=DMARC1; tag. 

While not an error, 47.7% of domains with a valid DMARC record did not include a rua tag, meaning those domain owners are not receiving aggregate feedback to enable them to correct any SPF or DKIM configuration issues. 

73% of domains with a valid DMARC record did not include a ruf tag, depriving the domain owner of forensic feedback reports. Forensic reports are helpful to diagnose SPF and DKIM misconfigurations and can also help the domain owner see attempts to hijack their domain in near real time. 

DMARC Provider Correlation to Policy

DMARC records specify the domain owner’s policy for how they would like receivers to treat unauthenticated mail that uses their domain in the “From:” header. There are three DMARC policies:  

  • “None,” which indicates the domain owner would like no special treatment applied to messages which fail authentication.
  • “Quarantine,” which indicates the domain owner would like unauthenticated mail from their domain placed in a quarantine such as a spam folder.
  • “Reject,” which indicates the domain owner would like the receiving organization to block the message outright, typically by issuing a 550 error at the end of the DATA portion of the SMTP transaction. 

Receivers may honor the domain owner’s wishes or may override the sender’s DMARC policy for a variety of reasons specific to the receiving organization. 

For maximum security, domain owners should publish a DMARC reject policy. This is often a difficult task, as it requires the domain owner to ensure that all legitimate email from their domain is properly authenticated with SPF and/or DKIM. The complexities of identifying all third-party senders and then working with those senders to ensure they follow DMARC-compatible authentication practices have led many companies to work with third parties who specialize in DMARC implementation. 

Our analysis of the top 10 million internet domains found that only 22.9% of domains who send their DMARC reporting data to themselves have a DMARC reject policy. 72.8% of domains whose DMARC records point to Fortra, publish DMARC reject policies. The chart below shows the policy breakdown for the major DMARC solution providers. The data suggests that working with a third-party vendor who specializes in DMARC implementations can increase the likelihood of achieving DMARC reject status. 

<Image Redacted for Email>

Conclusions

This analysis of the DNS and email authentication configurations of the top 10 million internet domains reveals both encouraging trends and significant shortcomings in the global state of email security. While the adoption of foundational protocols like SPF and DMARC has increased in recent years, the data shows a concerning level of misconfiguration, underutilization, and overall neglect — leaving the majority of domains vulnerable to spoofing, phishing, and business email compromise. 

While tools and standards exist to dramatically reduce spoofing and phishing risk, their protection is only as good as their implementation. The internet’s most visited domains include both shining examples of secure configuration and gaping vulnerabilities waiting to be exploited. Strengthening global email hygiene requires not only broader adoption of standards like SPF and DMARC, but also a concerted effort to ensure they are implemented correctly — and supported by the right infrastructure, partnerships, and oversight.