Critical FortiGate 100F SSL-VPN Vulnerability Exploited

Critical FortiGate 100F SSL-VPN Vulnerability Exploited

During an external pentesting, our red team identified a critical vulnerability on FortiGate 100F firewall appliances. The issue is CVE-2022-42475 – a heap-based buffer overflow in FortiOS’s SSL-VPN service that allows remote, unauthenticated code execution.

read more
Oracle ILOM Compromise via EternalBlue

Oracle ILOM Compromise via EternalBlue

During a penetration testing assessment, our team identified a critical exploitation chain affecting an enterprise network. The attack began by exploiting the EternalBlue vulnerability on an unpatched Windows server, allowing remote code execution.

read more