CyberWire Daily cover image

CyberWire Daily

A giant FortiJump for cybercriminals.

Oct 24, 2024
Eric Herzog, CMO of Infinidat, shares insights on the intersection of cybersecurity and storage resilience. He discusses the urgent need for businesses to adapt their data protection strategies in light of escalating cyber threats. Herzog highlights how traditional backup methods fall short and advocates for a collaborative approach to disaster preparedness. The conversation delves into the complexities of modern cybercriminal tactics and emphasizes innovative strategies to bolster defense mechanisms against both cyber attacks and natural disasters.
38:08

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • The recently discovered FortaJump zero-day vulnerability in Fortinet has been exploited since June, posing serious risks to sensitive data management.
  • The emergence of the Embargo ransomware group reflects the evolution of cyber threats, utilizing advanced methods and a ransomware-as-a-service model.

Deep dives

Zero-Day Vulnerability in Fortinet

A recently confirmed zero-day vulnerability in Fortinet's FortaManager, known as FortaJump, poses serious security risks as it has been actively exploited since June 2024. This flaw allows attackers to execute commands on FortiManager servers, potentially compromising sensitive data from managed FortiGate devices. Cybersecurity firm Mandiant reported that the threat actor UNC5820 has targeted over 50 servers using this vulnerability, registering their own FortiManager devices with valid certificates to gain unauthorized access. Fortinet advises customers to apply patches and restrict IP connections as mitigation measures to prevent further exploitation.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode