Fortiguard Labs

Outbreak Alerts

Protect and detect emerging threats that have large ramifications to the organizations and industries.

Latest Reports

events-logo Publications

[Barb'hack 2025] Decompile Linux malware with r2ai
Sep 01, 2025

About reversing 2 Linux malware with AI assistance. Learn to spot AI errors + learn to tweak your context size and prompt to get the best results.

signalreport-logo Threat Signal Report

ShadowSilk Data Exfiltration Attack
Aug 28, 2025

Nearly three dozen organizations across Central Asia and the Asia-Pacific region, predominantly government agencies, have been compromised in data exfiltration campaigns attributed to the Russian...

fortiguardblog-logo Threat Research Blog

Phishing Campaign Targeting Companies via UpCrypter
Aug 25, 2025

FortiGuard Labs uncovers a phishing campaign using fake emails and UpCrypter malware to deliver RATs like PureHVNC and DCRat across industries.      

fortiguardblog-logo Threat Research Blog

The Resurgence of IoT Malware: Inside the Mirai-Based Botnet Campaign
Aug 22, 2025

FortiGuard Labs analyzes the botnet campaign, a Mirai variant targeting global sectors. Learn its tactics, C2 methods, and Fortinet defenses.      

fortiguardblog-logo Threat Research Blog

The Resurgence of IoT Malware: Inside the Mirai-Based “Gayfemboy” Botnet Campaign
Aug 22, 2025

FortiGuard Labs analyzes the Gayfemboy botnet, a Mirai variant targeting global sectors. Learn its tactics, C2 methods, and Fortinet defenses.      

signalreport-logo Threat Signal Report

Multiple ZTNA Products Authentication Bypass
Aug 14, 2025

A series of critical vulnerabilities affecting leading zero trust platforms - Zscaler, Netskope, and Check Point (Perimeter 81) - have been disclosed following a seven-month research campaign by...

fortiguardblog-logo Threat Research Blog

From ClickFix to Command: A Full PowerShell Attack Chain
Aug 11, 2025

A regionally targeted PowerShell-based campaign used phishing lures, obfuscation, and RAT delivery to infiltrate Israeli organizations. Learn how the attack chain worked—and how Fortinet blocked it.      

fortiguardblog-logo Threat Research Blog

Unveiling a New Variant of the DarkCloud Campaign
Aug 07, 2025

FortiGuard Labs has uncovered a stealthy new variant of DarkCloud malware that leverages phishing emails, obfuscated JavaScript, PowerShell loaders, and process hollowing to exfiltrate...

outbreakalert-logo Outbreak Alert

Citrix Bleed 2
Aug 06, 2025

FortiGuard Labs has observed a sharp increase in exploitation attempts targeting the 'Citrix Bleed 2' vulnerability since July 28, 2025. Telemetry indicates activity has surged to over 6,000...

fortiguardblog-logo Threat Research Blog

Malicious Packages Across Open-Source Registries: Detection Statistics and Trends (Q2 2025)
Aug 04, 2025

Malware threats continue to infiltrate open-source software registries. FortiGuard Labs’ Q2 2025 analysis reveals persistent tactics used in malicious NPM and PyPI packages, including credential...

outbreakalert-logo Outbreak Alert

Microsoft SharePoint Zero-day Attack
Jul 31, 2025

FortiGuard Labs has detected and successfully blocked hundreds of exploitation attempts targeting a newly discovered zero-day vulnerability chain in on-premises Microsoft SharePoint servers. This...

fortiguardblog-logo Threat Research Blog

In-Depth Analysis of an Obfuscated Web Shell Script
Jul 25, 2025

Detailed analysis of an obfuscated web shell used in a CNI attack. Explores its structure, traffic patterns, and Fortinet’s detection and protection.      

fortiguardblog-logo Threat Research Blog

Inside The ToolShell Campaign
Jul 25, 2025

FortiGuard Labs uncovers ToolShell, a sophisticated exploit chain targeting Microsoft SharePoint servers using a mix of patched and zero-day CVEs. Learn how attackers deploy GhostWebShell and...

fortiguardblog-logo Threat Research Blog

A Special Mission to Nowhere
Jul 23, 2025

Following the Israel-Iran ceasefire, FortiGuard Labs uncovered a phishing campaign posing as a private jet evacuation service from Tel Aviv to New York. Learn how attackers used crisis-driven fear...

fortiguardblog-logo Threat Research Blog

NailaoLocker Ransomware’s “Cheese”
Jul 18, 2025

FortiGuard Labs analyzes NailaoLocker ransomware, a unique variant using SM2 encryption and a built-in decryption function. Learn how it works, why it matters, and how Fortinet protects against it.      

outbreakalert-logo Outbreak Alert

SonicWall Secure Mobile Access Attack
Jul 18, 2025

A campaign targeting SonicWall SMA 100 series appliances is currently under active exploitation, leveraging both known vulnerabilities and potential zero-days to gain persistent access to...

fortiguardblog-logo Threat Research Blog

Improving Cloud Intrusion Detection and Triage with FortiCNAPP Composite Alerts
Jul 17, 2025

FortiCNAPP Composite Alerts link weak signals into clear timelines—helping security teams detect cloud-native threats earlier and triage them faster.      

fortiguardblog-logo Threat Research Blog

Old Miner, New Tricks
Jul 16, 2025

FortiCNAPP Labs uncovers Lcrypt0rx, a likely AI-generated ransomware variant used in updated H2Miner campaigns targeting cloud resources for Monero mining.      

events-logo Publications

[Barb'hack 2025] Decompile Linux malware with r2ai
Sep 01, 2025

About reversing 2 Linux malware with AI assistance. Learn to spot AI errors + learn to tweak your context size and prompt to get the best results.

signalreport-logo Threat Signal Report

ShadowSilk Data Exfiltration Attack
Aug 28, 2025

Nearly three dozen organizations across Central Asia and the Asia-Pacific region, predominantly government agencies, have been compromised in data exfiltration campaigns attributed to the Russian...

fortiguardblog-logo Threat Research Blog

Phishing Campaign Targeting Companies via UpCrypter
Aug 25, 2025

FortiGuard Labs uncovers a phishing campaign using fake emails and UpCrypter malware to deliver RATs like PureHVNC and DCRat across industries.      

fortiguardblog-logo Threat Research Blog

The Resurgence of IoT Malware: Inside the Mirai-Based Botnet Campaign
Aug 22, 2025

FortiGuard Labs analyzes the botnet campaign, a Mirai variant targeting global sectors. Learn its tactics, C2 methods, and Fortinet defenses.      

fortiguardblog-logo Threat Research Blog

The Resurgence of IoT Malware: Inside the Mirai-Based “Gayfemboy” Botnet Campaign
Aug 22, 2025

FortiGuard Labs analyzes the Gayfemboy botnet, a Mirai variant targeting global sectors. Learn its tactics, C2 methods, and Fortinet defenses.      

signalreport-logo Threat Signal Report

Multiple ZTNA Products Authentication Bypass
Aug 14, 2025

A series of critical vulnerabilities affecting leading zero trust platforms - Zscaler, Netskope, and Check Point (Perimeter 81) - have been disclosed following a seven-month research campaign by...

fortiguardblog-logo Threat Research Blog

From ClickFix to Command: A Full PowerShell Attack Chain
Aug 11, 2025

A regionally targeted PowerShell-based campaign used phishing lures, obfuscation, and RAT delivery to infiltrate Israeli organizations. Learn how the attack chain worked—and how Fortinet blocked it.      

fortiguardblog-logo Threat Research Blog

Unveiling a New Variant of the DarkCloud Campaign
Aug 07, 2025

FortiGuard Labs has uncovered a stealthy new variant of DarkCloud malware that leverages phishing emails, obfuscated JavaScript, PowerShell loaders, and process hollowing to exfiltrate...

outbreakalert-logo Outbreak Alert

Citrix Bleed 2
Aug 06, 2025

FortiGuard Labs has observed a sharp increase in exploitation attempts targeting the 'Citrix Bleed 2' vulnerability since July 28, 2025. Telemetry indicates activity has surged to over 6,000...

fortiguardblog-logo Threat Research Blog

Malicious Packages Across Open-Source Registries: Detection Statistics and Trends (Q2 2025)
Aug 04, 2025

Malware threats continue to infiltrate open-source software registries. FortiGuard Labs’ Q2 2025 analysis reveals persistent tactics used in malicious NPM and PyPI packages, including credential...

outbreakalert-logo Outbreak Alert

Microsoft SharePoint Zero-day Attack
Jul 31, 2025

FortiGuard Labs has detected and successfully blocked hundreds of exploitation attempts targeting a newly discovered zero-day vulnerability chain in on-premises Microsoft SharePoint servers. This...

fortiguardblog-logo Threat Research Blog

In-Depth Analysis of an Obfuscated Web Shell Script
Jul 25, 2025

Detailed analysis of an obfuscated web shell used in a CNI attack. Explores its structure, traffic patterns, and Fortinet’s detection and protection.      

fortiguardblog-logo Threat Research Blog

Inside The ToolShell Campaign
Jul 25, 2025

FortiGuard Labs uncovers ToolShell, a sophisticated exploit chain targeting Microsoft SharePoint servers using a mix of patched and zero-day CVEs. Learn how attackers deploy GhostWebShell and...

fortiguardblog-logo Threat Research Blog

A Special Mission to Nowhere
Jul 23, 2025

Following the Israel-Iran ceasefire, FortiGuard Labs uncovered a phishing campaign posing as a private jet evacuation service from Tel Aviv to New York. Learn how attackers used crisis-driven fear...

fortiguardblog-logo Threat Research Blog

NailaoLocker Ransomware’s “Cheese”
Jul 18, 2025

FortiGuard Labs analyzes NailaoLocker ransomware, a unique variant using SM2 encryption and a built-in decryption function. Learn how it works, why it matters, and how Fortinet protects against it.      

outbreakalert-logo Outbreak Alert

SonicWall Secure Mobile Access Attack
Jul 18, 2025

A campaign targeting SonicWall SMA 100 series appliances is currently under active exploitation, leveraging both known vulnerabilities and potential zero-days to gain persistent access to...

fortiguardblog-logo Threat Research Blog

Improving Cloud Intrusion Detection and Triage with FortiCNAPP Composite Alerts
Jul 17, 2025

FortiCNAPP Composite Alerts link weak signals into clear timelines—helping security teams detect cloud-native threats earlier and triage them faster.      

fortiguardblog-logo Threat Research Blog

Old Miner, New Tricks
Jul 16, 2025

FortiCNAPP Labs uncovers Lcrypt0rx, a likely AI-generated ransomware variant used in updated H2Miner campaigns targeting cloud resources for Monero mining.      

events-logo Publications

[Barb'hack 2025] Decompile Linux malware with r2ai
Sep 01, 2025

About reversing 2 Linux malware with AI assistance. Learn to spot AI errors + learn to tweak your context size and prompt to get the best results.

signalreport-logo Threat Signal Report

ShadowSilk Data Exfiltration Attack
Aug 28, 2025

Nearly three dozen organizations across Central Asia and the Asia-Pacific region, predominantly government agencies, have been compromised in data exfiltration campaigns attributed to the Russian...

fortiguardblog-logo Threat Research Blog

Phishing Campaign Targeting Companies via UpCrypter
Aug 25, 2025

FortiGuard Labs uncovers a phishing campaign using fake emails and UpCrypter malware to deliver RATs like PureHVNC and DCRat across industries.      

fortiguardblog-logo Threat Research Blog

The Resurgence of IoT Malware: Inside the Mirai-Based Botnet Campaign
Aug 22, 2025

FortiGuard Labs analyzes the botnet campaign, a Mirai variant targeting global sectors. Learn its tactics, C2 methods, and Fortinet defenses.      

fortiguardblog-logo Threat Research Blog

The Resurgence of IoT Malware: Inside the Mirai-Based “Gayfemboy” Botnet Campaign
Aug 22, 2025

FortiGuard Labs analyzes the Gayfemboy botnet, a Mirai variant targeting global sectors. Learn its tactics, C2 methods, and Fortinet defenses.      

signalreport-logo Threat Signal Report

Multiple ZTNA Products Authentication Bypass
Aug 14, 2025

A series of critical vulnerabilities affecting leading zero trust platforms - Zscaler, Netskope, and Check Point (Perimeter 81) - have been disclosed following a seven-month research campaign by...

fortiguardblog-logo Threat Research Blog

From ClickFix to Command: A Full PowerShell Attack Chain
Aug 11, 2025

A regionally targeted PowerShell-based campaign used phishing lures, obfuscation, and RAT delivery to infiltrate Israeli organizations. Learn how the attack chain worked—and how Fortinet blocked it.      

fortiguardblog-logo Threat Research Blog

Unveiling a New Variant of the DarkCloud Campaign
Aug 07, 2025

FortiGuard Labs has uncovered a stealthy new variant of DarkCloud malware that leverages phishing emails, obfuscated JavaScript, PowerShell loaders, and process hollowing to exfiltrate...

outbreakalert-logo Outbreak Alert

Citrix Bleed 2
Aug 06, 2025

FortiGuard Labs has observed a sharp increase in exploitation attempts targeting the 'Citrix Bleed 2' vulnerability since July 28, 2025. Telemetry indicates activity has surged to over 6,000...

fortiguardblog-logo Threat Research Blog

Malicious Packages Across Open-Source Registries: Detection Statistics and Trends (Q2 2025)
Aug 04, 2025

Malware threats continue to infiltrate open-source software registries. FortiGuard Labs’ Q2 2025 analysis reveals persistent tactics used in malicious NPM and PyPI packages, including credential...

outbreakalert-logo Outbreak Alert

Microsoft SharePoint Zero-day Attack
Jul 31, 2025

FortiGuard Labs has detected and successfully blocked hundreds of exploitation attempts targeting a newly discovered zero-day vulnerability chain in on-premises Microsoft SharePoint servers. This...

fortiguardblog-logo Threat Research Blog

In-Depth Analysis of an Obfuscated Web Shell Script
Jul 25, 2025

Detailed analysis of an obfuscated web shell used in a CNI attack. Explores its structure, traffic patterns, and Fortinet’s detection and protection.      

fortiguardblog-logo Threat Research Blog

Inside The ToolShell Campaign
Jul 25, 2025

FortiGuard Labs uncovers ToolShell, a sophisticated exploit chain targeting Microsoft SharePoint servers using a mix of patched and zero-day CVEs. Learn how attackers deploy GhostWebShell and...

fortiguardblog-logo Threat Research Blog

A Special Mission to Nowhere
Jul 23, 2025

Following the Israel-Iran ceasefire, FortiGuard Labs uncovered a phishing campaign posing as a private jet evacuation service from Tel Aviv to New York. Learn how attackers used crisis-driven fear...

fortiguardblog-logo Threat Research Blog

NailaoLocker Ransomware’s “Cheese”
Jul 18, 2025

FortiGuard Labs analyzes NailaoLocker ransomware, a unique variant using SM2 encryption and a built-in decryption function. Learn how it works, why it matters, and how Fortinet protects against it.      

outbreakalert-logo Outbreak Alert

SonicWall Secure Mobile Access Attack
Jul 18, 2025

A campaign targeting SonicWall SMA 100 series appliances is currently under active exploitation, leveraging both known vulnerabilities and potential zero-days to gain persistent access to...

fortiguardblog-logo Threat Research Blog

Improving Cloud Intrusion Detection and Triage with FortiCNAPP Composite Alerts
Jul 17, 2025

FortiCNAPP Composite Alerts link weak signals into clear timelines—helping security teams detect cloud-native threats earlier and triage them faster.      

fortiguardblog-logo Threat Research Blog

Old Miner, New Tricks
Jul 16, 2025

FortiCNAPP Labs uncovers Lcrypt0rx, a likely AI-generated ransomware variant used in updated H2Miner campaigns targeting cloud resources for Monero mining.      

Certifications

  • av comparatives logo
  • common criteria logo
  • nss labs logo
  • vb logo
  • mitre logo

This site uses cookies. Some are essential to the operation of the site; others help us improve the user experience. By continuing to use the site, you consent to the use of these cookies. To learn more about cookies, please read our privacy policy.