Fortinet Threat Research

Fortinet Threat Research.

Fortinet Threat Research Blog Official blog feed of Fortinet

  • Inside The ToolShell Campaign
    on July 25, 2025 at 1:00 pm

    FortiGuard Labs uncovers ToolShell, a sophisticated exploit chain targeting Microsoft SharePoint servers using a mix of patched and zero-day CVEs. Learn how attackers deploy GhostWebShell and KeySiphon for stealthy remote code execution and credential theft.      

  • In-Depth Analysis of an Obfuscated Web Shell Script
    on July 25, 2025 at 1:00 pm

    Detailed analysis of an obfuscated web shell used in a CNI attack. Explores its structure, traffic patterns, and Fortinet’s detection and protection.      

  • A Special Mission to Nowhere
    on July 23, 2025 at 1:00 pm

    Following the Israel-Iran ceasefire, FortiGuard Labs uncovered a phishing campaign posing as a private jet evacuation service from Tel Aviv to New York. Learn how attackers used crisis-driven fear to steal personal and financial data.      

  • NailaoLocker Ransomware’s “Cheese”
    on July 18, 2025 at 1:00 pm

    FortiGuard Labs analyzes NailaoLocker ransomware, a unique variant using SM2 encryption and a built-in decryption function. Learn how it works, why it matters, and how Fortinet protects against it.      

  • Improving Cloud Intrusion Detection and Triage with FortiCNAPP Composite Alerts
    on July 17, 2025 at 1:00 pm

    FortiCNAPP Composite Alerts link weak signals into clear timelines—helping security teams detect cloud-native threats earlier and triage them faster.      

  • Old Miner, New Tricks
    on July 16, 2025 at 1:00 pm

    FortiCNAPP Labs uncovers Lcrypt0rx, a likely AI-generated ransomware variant used in updated H2Miner campaigns targeting cloud resources for Monero mining.      

  • How FortiSandbox 5.0 Detects Dark 101 Ransomware Despite Evasion Techniques
    on July 14, 2025 at 1:00 pm

    Discover how FortiSandbox 5.0 detects Dark 101 ransomware, even with sandbox evasion tactics. Learn how advanced behavioral analysis blocks file encryption, system tampering, and ransom note deployment.      

  • Catching Smarter Mice with Even Smarter Cats
    on July 10, 2025 at 1:00 pm

    Explore how AI is changing the cat-and-mouse dynamic of cybersecurity, from cracking obfuscation and legacy languages to challenging new malware built with Flutter, Rust, and Delphi.      

  • NordDragonScan: Quiet Data-Harvester on Windows
    on July 7, 2025 at 1:00 pm

    FortiGuard Labs explores how NordDragonScan utilizes an effective distribution network for dissemination. Learn more.      

  • RondoDox Unveiled: Breaking Down a New Botnet Threat
    on July 3, 2025 at 1:00 pm

    FortiGuard Labs analyzes RondoDox, a stealthy new botnet targeting TBK DVRs and Four-Faith routers via CVE-2024-3721 and CVE-2024-12856. Learn how it evades detection, establishes persistence, and mimics gaming and VPN traffic to launch DDoS attacks.      

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.