“Fortinet” — 50 distilled results

CISA cybersecurity vulnerability alerts (multiple CVEs)

Six critical and high-severity vulnerabilities disclosed: DD-WRT stack buffer overflow (CVE-2021-27137), Langflow code execution flaws (CVE-2026-0770, CVE-2026-55255), WordPress Core interpretation conflict (CVE-2026-63030), Microsoft AD FS access control gap (CVE-2026-56155), and Oracle E-Business Suite privilege escalation (CVE-2026-46817). All pose remote compromise risks.

Cybersecurity Incident News Feed

Infosec.exchange publishes unrelated security stories including AI chatbot data exposure, vulnerability disclosures across web forums and mobile OS, and defensive security policy measures. Stories span multiple technology domains with no unifying incident or narrative.

CISA adds multiple critical vulnerabilities to known exploited catalog

Between September 8 and 11, 2026, the U.S. Cybersecurity and Infrastructure Security Agency added six critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Microsoft Windows, GitLab, JFrog Artifactory, and N-able N-central that allow remote code execution and privilege escalation. Active exploitation of these vulnerabilities has been documented.

json:cisa-kev 20d ago

Cisco Firewall Management Center vulnerabilities actively exploited

Cisco Talos confirmed on September 10, 2026, that CVE-2026-20079 and CVE-2026-20316, maximum-severity vulnerabilities in Cisco Secure Firewall Management Center (FMC), were being actively exploited by state-sponsored actors, ransomware gangs, and financially motivated threat groups. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities list on September 9.

New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs

New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs. #hackernews #news Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs.

‼️🇦🇪 A threat actor is offering admin-level Fortinet SSL-VPN access into an undisclosed UAE-based hotel reservations company with reported revenue of $17 million and 1,450 network hosts, priced at $

‼️🇦🇪 A threat actor is offering admin-level Fortinet SSL-VPN access into an undisclosed UAE-based hotel reservations company with reported revenue of $17 million and 1,450 network hosts, priced at $700. 💥 No delays.

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.