Severity: Informational

FortiBleed Attackers Locking Victims Out of Fortinet Devices

Attackers are creating new accounts and deleting existing ones and passwords to prevent legitimate access.

Excerpt from the primary source: SecurityWeek

Who is affected

Home users · Small businesses · Enterprises

Affected technology: FortiGate / FortiOS

What you should do

No specific action is required at this time.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Original reporting

FortiBleed Attackers Locking Victims Out of Fortinet Devices SecurityWeek · securityweek.com · Oct 8, 2026 · Primary source
Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Fortinet FortiMail Path Traversal Vulnerability (CVE-2026-104286) is being actively exploited, CISA warns

CISA added CVE-2026-104286 (Fortinet FortiMail) to its Known Exploited Vulnerabilities catalog on October 1, 2026, which means there is reliable evidence of exploitation in the wild. Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or…

Why it matters

CISA lists this as exploited in the wild. Unpatched FortiGate / FortiOS and FortiMail systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: ElevatedAction: Be aware

Apple’s Verified Photography System

Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer. It can also verify that multiple images came from the same iPhone. Other industry solutions require a photographer or institution to vouch for an image using their own credentials. We are concerned this puts some photographers, such as…

Severity: ElevatedAction: Be aware

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.

FortiBleed Attackers Locking Victims Out of Fortinet Devices | CybersecurityNews.us