Cyber Threat Report: 'Holding down the Fortinet vulnerability'
Report Author | Red Canary |
---|---|
Publication Date | 2024-04-08 |
Original Reporting | Source |
Identified CVEs | CVE-2023-48788 |
This report from Red Canary outlines activity they have observed related to the exploitation of CVE-2023-48788 in FortiClient enterprise management servers (FortiClient EMS). According to the report, adversaries have been observed exploiting the vulnerability to install unauthorised RMM (remote management and monitoring) tools and PowerShell backdoors. The report includes technical details of adversary behaviour and recommendations for protection (patching) and detection.
Cyber Threat Graph Context
Explore how this report relates to the wider threat graph