Tech

Update now — Fortinet Windows VPN hacked to steal user data

Share
Share


  • Researchers spot Chinese threat actor stealing login credentials from Fortinet VPN
  • Thefts carried out with the help of a vulnerability discovered in 2023
  • The bug is yet to be addressed, or even assigned a CVE

Cybersecurity researchers has revealed that for months now, Fortinet’s Windows VPN client has been vulnerable to a flaw which allows threat actors to steal user credentials – and Chinese hackers have reportedly now started exploiting the bug and stealing the data.

Experts from Volexity have published an in-depth report on a piece of malware called DeepData. This malware was used by a Chinese threat actor known as BrazenBamboo to steal login credentials, and VPN server information from Fortinet VPNs.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Many companies are only hiring “responsible AI” jobs to boost their image
Tech

Many companies are only hiring “responsible AI” jobs to boost their image

Report claims mentions of “responsible AI” (and similar) are on the rise...

Australian trial says tech for social media teen ban can work
Tech

Australian trial says tech for social media teen ban can work

An Australian ban on under-16s joining social media sites is due to...

Mystery of M&S hack deepens as TCS claims none of its systems were compromised
Tech

Mystery of M&S hack deepens as TCS claims none of its systems were compromised

TCS says none of its systems or users were affected in Marks...