Why Should I Care? โ 2026-08-13 | ๐ด 0 HIGH ยท ๐ก 3 MEDIUM ยท ๐ต 21 RADAR ยท โช 233 FILTERED
๐ Briefing โ 2026-08-13
24 vendor intel items scanned | ๐ด 0 HIGH | ๐ก 3 MEDIUM | ๐ต 21 RADAR | โช 233 FILTERED
โ No critical items today.
Everything else can wait.
๐ก Medium โ review when time permits:
- Heap overflow in kernel driver due to missing size validation โ Yes, if you run FortiClient Windows: unauthenticated RCE via malicious DNS responses.
- FGFM Authentication Weakening via CLI Configuration โ Yes, if you run FortiManager or FortiManager Cloud with a specific CLI option set: unauthenticated attackers can impersonate any managed FortiGate device.
- Broken access control in the RADIUS type admin group โ Yes, if you run FortiWeb with Remote Radius Type Admin Authentication configured: unauthenticated access to GUI/CLI allows full control.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
No HIGH priority items in the last 24h.
Why Should I Care? ๐ก MEDIUM (3)
Heap overflow in kernel driver due to missing size validation
Fortinet PSIRT | CVSS 7.3
โ Why Should I Care?
Yes, if you run FortiClient Windows: unauthenticated RCE via malicious DNS responses. Patch now.
๐ฏ Affected versions: FortiClient Windows versions prior to the patched version
๐ญ In plain English:
If you use FortiClient on a Windows machine, an attacker can send specially crafted DNS responses that exploit a flaw in the software, allowing them to run any code they want on your computer without needing your password. This means they could take full control of your system and do anything from stealing files to installing malware.
๐ง Prerequisites:
- Attacker must be able to intercept or alter DNS traffic
- FortiClient Windows version is vulnerable
โฑ Urgency: High urgency due to the potential for unauthenticated remote code execution, which could lead to full system compromise.
๐ก Context: The kernel driver in FortiClient does not properly validate the size of input data when processing DNS responses, leading to a heap overflow.
FGFM Authentication Weakening via CLI Configuration
Fortinet PSIRT | CVSS 7.3
โ Why Should I Care?
Yes, if you run FortiManager or FortiManager Cloud with a specific CLI option set: unauthenticated attackers can impersonate any managed FortiGate device. Patch immediately.
๐ฏ Affected versions: FortiManager and FortiManager Cloud with the specific CLI option set
๐ญ In plain English:
An attacker can pretend to be any of your managed FortiGate devices by sending special requests, if they have a valid certificate. This means they could potentially take control of your network configurations without needing to know any passwords.
๐ง Prerequisites:
- Specific CLI option set
- Valid certificate
โฑ Urgency: High urgency due to the potential for unauthenticated impersonation and unauthorized access to managed devices.
Broken access control in the RADIUS type admin group
Fortinet PSIRT | CVSS 8.8
โ Why Should I Care?
Yes, if you run FortiWeb with Remote Radius Type Admin Authentication configured: unauthenticated access to GUI/CLI allows full control. Patch immediately.
๐ฏ Affected versions: FortiWeb versions with Remote Radius Type Admin Authentication enabled
Not affected: All FortiWeb versions without Remote Radius Type Admin Authentication configured
๐ญ In plain English:
An attacker can log into your firewall's admin interface using any username and password, gaining full control over the device. They could change settings, monitor traffic, or even shut down security features.
๐ง Prerequisites:
- Remote Radius Type Admin Authentication must be enabled
โฑ Urgency: High urgency due to potential for unauthenticated access allowing complete takeover of the device.
Why Should I Care? ๐ต On the Radar (21)
- Lazarus hackers exploited Windows zero-day to target defense firms (BleepingComputer) โ North Korean hackers used a new Windows bug to break into defense firms. They tricked employees into downloading malware that gives full control over the system. If you're in defense, aerospace, or aviation and use Windows, this affects you directly.
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS (The Hacker News) โ A critical flaw in Cisco's firewall software (ASA and FTD) allows attackers to trigger a denial-of-service (DoS), potentially disrupting your network operations. If you're running affected versions of ASA or FTD, immediate action is needed to patch the vulnerability.
- Hackers exploit critical Adobe Commerce flaw to hijack customer accounts (BleepingComputer) โ A serious flaw in Adobe Commerce and Magento allows hackers to take over customer accounts. If your business uses these platforms, immediate action is needed to apply the latest security update.
- "City-Forum" data-theft attacks target Salesforce, ServiceNow portals (BleepingComputer) โ A group called City-Forum is stealing data from companies using Salesforce Experience Cloud and ServiceNow portals by exploiting overly permissive sharing rules. They target guest accounts that have access to more data than they should, potentially exposing sensitive records.
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor (The Hacker News) โ The Lazarus Group exploited a recently patched flaw in Windows to deploy a backdoor targeting defense and aerospace companies. If you're in these sectors, this means your systems could have been compromised without your knowledge.
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One (The Hacker News) โ A large number of fake Chrome VPN extensions are routing users' traffic through unauthorized proxies. This can compromise privacy and potentially allow attackers to intercept sensitive information.
- Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer) โ Hackers are exploiting a new critical vulnerability in Microsoft SharePoint that lets them impersonate users and access sensitive data. If you run SharePoint, ensure your systems are patched to avoid unauthorized access.
- Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations (The Hacker News) โ Two malicious versions of LiteLLM were briefly available on PyPI in March. If your systems installed these versions, they could have stolen various credentials from your infrastructure. This affects any organization that used or depended on LiteLLM during the exposure window.
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access (The Hacker News) โ Hackers are exploiting a critical flaw in VMware vCenter that lets them take over servers. If your infrastructure uses this product, you need to patch it immediately to avoid unauthorized access.
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws (The Hacker News) โ Adobe has patched critical security flaws in ColdFusion and Campaign Classic that could allow attackers to execute arbitrary code and escalate privileges. This means your systems could be compromised if you don't update immediately.
- New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges (BleepingComputer) โ A new zero-day exploit named 'ShieldBreak' has been released that can bypass Microsoft Defender's security measures on fully patched Windows systems, granting attackers SYSTEM-level access. This means any system using Microsoft Defender is at risk of being compromised by this vulnerability.
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access (The Hacker News) โ A new security flaw called ShieldBreak allows attackers to bypass a recent patch in Microsoft Defender, potentially giving them full control over your system. If you're running Windows 11 or Server 2025 with Defender, this could be a significant risk.
- SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code (The Hacker News) โ A critical security flaw in SAP Commerce Cloud could allow anyone to run malicious code on your system without needing any login credentials. This means they could potentially take control of your application and access sensitive data.
- Android malware combo takes out loans and relays victims' credit cards (BleepingComputer) โ A new malware combo called WindRelay and SpyNote is stealing credit card information from Android phones by tricking victims into installing malicious apps. This can lead to unauthorized transactions and loan applications in the victim's name.
- Plug and Pwn attack uses fake USB devices for Windows SYSTEM access (BleepingComputer) โ Security researchers have found a way to exploit the Windows Plug and Play feature using fake USB devices or remote connections to gain SYSTEM privileges. This means attackers can install malicious software that runs with high-level permissions, potentially compromising your entire network.
โช 233 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 9 vendor feeds | CISA KEV