Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Fortinet Blog

10 articles

Fortinet Blog vendor Jul 22

Inside a TrickBot Variant Using DNS Tunneling for C2

FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and obfuscation techniques

T1027 T1071 T1572

Fortinet Blog → Details

Fortinet Blog vendor Jul 16

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.

T1566

Fortinet Blog → Details

Fortinet Blog vendor Jul 1

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs, steganography, and evasive C2.

T1566

Fortinet Blog → Details

Fortinet Blog vendor Amazon Jun 26

From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach

See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation, and led to Redshift breach activity detected by FortiCNAPP

Fortinet Blog → Details

Fortinet Blog vendor Jun 11

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process inject...

Fortinet Blog → Details

Fortinet Blog vendor Jun 4

Cybercriminals Are Targeting the FIFA World Cup 2026

FortiGuard Labs research shows how cybercriminals are exploiting the demand for the FIFA World Cup 2026 through phishing, fake tickets, malware, impersonatio...

T1566 T1078

Fortinet Blog → Details

Fortinet Blog vendor Jun 3

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.

Fortinet Blog → Details

Fortinet Blog vendor Oracle May 26

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data

T1566

Fortinet Blog → Details

Fortinet Blog vendor Kubernetes May 20

Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise

FortiGuard Labs analyzed several P2PInfect compromises in GKE clusters, showing how exposed Redis instances can enable persistent botnet enrollment, dormancy...

Fortinet Blog → Details

Fortinet Blog vendor Amazon May 15

PureLogs: Delivery via PawsRunner Steganography

FortiGuard Labs has analyzed a steganography-based malware campaign that uses PawsRunner to deliver the PureLogs infostealer, highlighting evolving delivery ...

Fortinet Blog → Details

FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA