More

    Update now — Fortinet Windows VPN hacked to steal user data




    • Researchers spot Chinese threat actor stealing login credentials from Fortinet VPN
    • Thefts carried out with the help of a vulnerability discovered in 2023
    • The bug is yet to be addressed, or even assigned a CVE

    Cybersecurity researchers has revealed that for months now, Fortinet’s Windows VPN client has been vulnerable to a flaw which allows threat actors to steal user credentials – and Chinese hackers have reportedly now started exploiting the bug and stealing the data.

    Experts from Volexity have published an in-depth report on a piece of malware called DeepData. This malware was used by a Chinese threat actor known as BrazenBamboo to steal login credentials, and VPN server information from Fortinet VPNs.

    https://cdn.mos.cms.futurecdn.net/gwSJ8yZfiGapWgo9WxBf9C-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img