Security News

Cybersecurity news aggregator

🛡️
CRITICAL Attacks SecurityWeek

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Threat actors are actively exploiting CVE-2025-25249, an unauthenticated heap-based buffer overflow (CVSS 8.1), to execute arbitrary code on Fortinet devices and deploy the AI-assisted PivotC2 RAT. Affected versions are FortiOS 6.4.0 through 6.4.16, 7.0.0 through 7.0.17, 7.2.0 through 7.2.11, 7.4.0 through 7.4.8, and 7.6.0 through 7.6.3. The vulnerability is patched in FortiOS versions 6.4.17, 7.0.18, 7.2.12, 7.4.9, and 7.6.4.
Read Full Article →

Malware & Threats Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026. By Ionut Arghire | September 10, 2026 (2:33 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug was patched in January in FortiOS and FortiSwitchManager. The flaw “may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests,” Fortinet noted in its advisory . This week, SOCRadar warned that hackers have been exploiting the security defect to deploy the PivotC2 RAT on vulnerable devices. A FortiGate post-exploitation tool, the backdoor provides attackers with interactive shell access, traffic tunneling, network scanning, and configuration harvesting capabilities. SOCRadar believes that PivotC2 was likely developed with the use of AI and that threat actors have been using it in attacks since at least July 2026. Advertisement. Scroll to continue reading. “The threat actors targeted more than 30,000 IP addresses, leading to the exploitation and infection of 178 devices with PivotC2,” SOCRadar says. The attacks mainly targeted US entities, where at least two intrusions have resulted in data exfiltration. According to the cybersecurity firm, the attacks are likely mounted by a Russian-speaking cybercrime actor. On Wednesday, the US cybersecurity agency CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities ( KEV ) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04’s requirements. Patches for the bug were rolled out in FortiOS versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18, and in FortiSwitchManager versions 7.2.7 and 7.0.6. All organizations are advised to update to these or newer versions. Related: Android’s September 2026 Updates Patch 180 Vulnerabilities Related: Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories Related: Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws Ivanti Patches Critical Flaws Across Enterprise Security Products Chrome 153 Patches Seventh Zero-Day of 2026 Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day Hackers Return $263 Million Stolen From Liquid Network SAP Patches Critical Extended Passport Processing Vulnerability MikroTik Patches Critical Flaws Chained to Hack Routers Latest News New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender HelmGuard Raises $7.3 Million for Agentic GRC and Security AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns Android’s September 2026 Updates Patch 180 Vulnerabilities Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the Move Frank Verdecanna has been appointed Chief Financial Officer at Armadin. Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America. Skyhigh Security has named Anthony Palladino as Chief Operating Officer. More People On The Move Expert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email

Share this article