پارتیان

FortiGuard Labs | FortiGuard Center - Threat Signal Report

The Threat Signal created by the FortiGuard Labs is intended to provide you with insight on emerging issues that are trending within the cyber threat landscape. The Threat Signal will provide concise technical details about the issue, mitigation recommendations and a perspective from the FortiGuard Labs team in an FAQ style format.

What is the Attack?

Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes.

While the reported activity specifically references Rockwell Automation/Allen-Bradley MicroLogix PLCs, the targeting is not necessarily limited to these products, and other internet-facing PLCs may also be at risk.

The activity does not involve a specific CVE. Instead, attackers are taking advantage of Internet-exposed PLCs, weak or default credentials, and inadequate access controls to obtain unauthorized access to OT environments.

Once access to an exposed PLC is obtained, attackers may manipulate configurations, operating parameters, or connected industrial processes. Such access can interfere with normal operations and potentially affect the availability and reliability of water and wastewater services.

What is the recommended Mitigation?

• Remove PLCs from direct Internet exposure and place them behind secure gateways, firewalls, or VPNs.
• Change default credentials and enforce strong, unique passwords for PLCs and associated OT systems.
• Implement access control lists (ACLs) to restrict communications to authorized devices and expected sources.
• Restrict remote access to OT environments and require secure authentication for authorized users.
• Monitor PLC configurations and network activity for unauthorized changes, including unexpected modifications to IP addresses, passwords, or operating parameters.
• Segment OT and IT networks to limit lateral movement following a compromise.
• Review exposed PLCs and other Internet-facing OT assets and remove unnecessary public access.
• Maintain offline backups of PLC configurations to support recovery if unauthorized changes or operational disruptions occur.

The FBI specifically recommends removing PLCs from direct Internet exposure, using strong unique passwords, and implementing ACLs to restrict communications

What FortiGuard Coverage is available?

• FortiGuard Operational Technology Security Service: Provides specialized protection for OT/ICS environments, helping identify and protect against threats targeting industrial control systems, including PLCs and other critical OT assets. OT App Detection | FortiGuard Labs
• FortiGuard IPS Service: Detects and blocks network-based attacks targeting exposed OT/ICS services and PLC infrastructure.
• FortiGuard Web Filtering: Blocks access to known malicious infrastructure associated with threat activity.
• FortiGuard Antivirus & Behavior Detection: Detects malicious payloads that may be delivered following network compromise.
• FortiGuard IOC Service: Identifies known indicators associated with malicious infrastructure and post-compromise activity.
• FortiGuard Incident Response: Supports investigation, containment, and recovery following an OT/ICS compromise.

What is the Attack?

U.S. cybersecurity agencies, including CISA, NSA, FBI, DOE, and EPA, have warned of an active cyber threat targeting Siemens S7 Series PLCs that are Internet-exposed, running outdated software, or otherwise inadequately protected.

The advisory highlights activity involving reconnaissance and unauthorized interaction with PLCs, including scanning of Internet-accessible industrial systems. Successful access to PLCs could allow threat actors to modify industrial processes, disrupt operations, manipulate control logic, introduce safety hazards and cause physical damage.

Organizations operating Siemens S7 Series PLCs should immediately assess Internet exposure, network segmentation, access controls, monitoring, and PLC-specific security configurations.

What is the recommended Mitigation?

1. Inventory Siemens S7 Series PLCs:
• Identify all Siemens S7 Series PLCs within the environment.
• Identify firmware versions and device details.
• Determine which PLCs are reachable from untrusted or external networks.
• Use FortiGuard Operational Technology Security Service (OTSS) for OT asset discovery and device identification.

2. Verify Network Segmentation:
• Ensure Siemens S7 PLCs are not directly accessible from the Internet.
• Restrict access to S7 communications, including TCP/102, to authorized systems.
• Segment OT networks from enterprise and corporate networks.
• Use DMZ architectures where communication between IT and OT is required.
• Restrict routing between untrusted networks and PLC environments.
• Apply appropriate controls to historian and monitoring communications to limit unauthorized write access.

FortiOS and FortiGate can enforce network segmentation, routing restrictions, and policy-based access controls, while OTSS provides OT-aware visibility and monitoring.

3. Strengthen Access Controls:
• Restrict PLC access to authorized engineering workstations and management systems.
• Use network access policies rather than relying solely on PLC IP/MAC allowlisting.
• Apply application controls to engineering workstations using FortiEDR.
• Require MFA for remote access to OT environments using FortiPAM and/or FortiGate.
• Minimize remote administrative access to PLCs and engineering systems.

4. Enable Comprehensive OT Monitoring and Logging:
Monitor for:
• Unauthorized S7 connections to PLCs.
• Unexpected S7 PUT/GET operations.
• Unauthorized PLC configuration or program changes.
• IP scanning and reconnaissance activity.
• S7 protocol scanning and enumeration.
• Unexpected communication with PLCs from enterprise or external networks.

FortiGuard OTSS provides OT-aware visibility and monitoring, while FortiGate/FortiGuard IPS can detect and block network activity targeting S7 services and protocols, including S7 scanning and enumeration activity.

5. Implement S7-Specific Hardening:
• Restrict access to PLC web interfaces and disable unnecessary services where supported.
• Disable unused protocols and services.
• Limit S7 communications to required source and destination systems.
• Review PLC security settings and engineering workstation configurations.
• Validate PLC programs, configurations, firmware, and logic for unauthorized changes.

What FortiGuard Coverage is available?

• FortiGuard Operational Technology Security Service (OTSS) – Provides OT asset discovery, device identification, protocol-aware monitoring, and security visibility for industrial environments, including Siemens S7 infrastructure. FortiGuard Labs
• FortiGate / FortiOS – Enforces network segmentation, access-control policies, routing restrictions, and controlled connectivity between enterprise, DMZ, and OT environments.
• FortiGuard IPS – Detects and blocks network-based attacks, scanning, enumeration, and suspicious activity targeting industrial protocols and services, including Siemens S7 communications.
• FortiEDR – Protects engineering workstations against malicious applications and unauthorized activity that could be used to compromise OT environments.
• FortiPAM – Provides privileged access management and supports stronger controls, including MFA, for administrative and remote access to critical systems.
• FortiGuard Network Detection and Response (NDR) – Provides additional network visibility and behavioral detection to identify anomalous activity within OT and IT environments.
• FortiGuard Incident Response – Supports investigation, containment, and recovery following suspected compromise of PLCs or OT infrastructure.

What is the Vulnerability?

FortiGuard Labs is tracking an exploitation risk associated with CVE-2026-42533, a heap-based buffer overflow vulnerability affecting NGINX Open Source and NGINX Plus. The flaw occurs when the map directive uses regex matching and capture variables in a specific configuration pattern. An unauthenticated remote attacker can send crafted HTTP requests that may crash the NGINX worker process, resulting in denial of service, and potentially achieve remote code execution when ASLR is disabled or bypassed.

The vulnerability was publicly disclosed by F5 on July 15, 2026, with NGINX releasing fixed versions the same day.

Fortinet has conducted an internal security review of products and services that use NGINX. Based on the current assessment, Fortinet products are not affected by CVE-2026-42533.

What is the Recommended Mitigation?

Affected products:
NGINX Open Source 0.9.6–1.30.3 and 1.31.0–1.31.2
NGINX Plus R33–R36
NGINX Plus R37 37.0.0.1–37.0.2.1
NGINX Ingress Controller, NGINX Gateway Fabric, NGINX App Protect WAF, and other F5/NGINX products with affected bundled versions.

Organizations should:
• Upgrade NGINX Open Source to 1.30.4 or 1.31.3 or later, depending on the deployment branch.
• Upgrade NGINX Plus to a fixed release, including R36 P7 or 37.0.3.1 where applicable.
• Review NGINX configurations for map directives using regex captures and confirm whether vulnerable variable-reference patterns are present.
• Prioritize Internet-facing NGINX deployments and reverse proxies.
• Deploy WAF protections to detect and block malicious HTTP requests targeting vulnerable NGINX configurations while patching is underway.
• Monitor NGINX worker-process crashes, abnormal HTTP requests, and other indicators of attempted exploitation.

What FortiGuard Coverage is available?

• FortiGuard IPS Service: Detects and blocks network-based attacks targeting vulnerable NGINX assets. Intrusion Prevention | FortiGuard Labs
• FortiWeb: Provides mitigation for CVE-2026-42533 through a custom signature and HTTP protocol constraint to help protect vulnerable NGINX deployments while patching is underway. Technical Tip: Defending against 2026-42533 with FortiWeb | Community
• FortiGuard Vulnerability Management: Identifies vulnerable NGINX assets and helps prioritize remediation based on exposure and risk.
• FortiGuard Incident Response Service: FortiGuard Incident Response Service assists organizations in investigating potential compromise, determining the scope of attacker activity, and supporting containment, remediation, and recovery efforts following exploitation.

What is the Attack?

FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack chain affecting WordPress Core. Unlike most WordPress attacks that rely on vulnerable plugins or themes, WP2Shell impacts the WordPress core application itself, allowing attackers to compromise default installations without requiring any plugins or authentication. Public proof-of-concept (PoC) exploits are widely available, and active exploitation has been reported shortly after technical details were disclosed.

Successful exploitation may allow attackers to:
• Execute arbitrary code on the web server.
• Create unauthorized administrator accounts.
• Deploy web shells or persistent backdoors.
• Steal sensitive website and database contents.
• Install malware or ransomware.
• Use compromised servers for further attacks.

What is the recommended Mitigation?

Affected Versions:
WordPress 6.9.0 – 6.9.4
WordPress 7.0.0 – 7.0.1
WordPress 7.1 Beta

Organizations should immediately:
• Upgrade WordPress to the latest patched release (6.9.5, 7.0.2, or later).
• Restrict unnecessary exposure of WordPress administrative interfaces.
• Monitor for unauthorized administrator account creation.
• Review web server logs for suspicious REST API batch endpoint requests.
• Scan for web shells and other indicators of compromise.
• Apply network protections capable of detecting SQL injection and exploitation attempts.

What FortiGuard Coverage is available?

  • FortiGuard IPS Service - Detects and blocks exploitation attempts targeting the WP2Shell vulnerability chain. Intrusion Prevention | FortiGuard Labs

  • FortiGuard Web Application Firewall (WAF) - Protects against SQL injection and malicious REST API requests. Web Application Security | FortiGuard Labs

  • FortiGuard Web Filtering - Blocks access to known malicious infrastructure.

  • FortiGuard Antivirus & Behavior Detection - Detects malware and web shells deployed after successful exploitation.

  • FortiGuard IOC Service - Identifies indicators associated with compromised WordPress servers.

  • FortiGuard Incident Response - Assists with investigation, containment, and recovery following compromise.

What is the Attack?

A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Management (PLM) systems to deploy web shells, steal intellectual property, and carry out double-extortion ransomware attacks.

The campaign chains a pre-authentication information disclosure vulnerability in the FlexPLM endpoint with CVE-2026-12569 to achieve unauthenticated remote code execution. Following compromise, attackers deploy JSP web shells, perform file system discovery, exfiltrate sensitive information, and ultimately issue ransom demands to affected organizations.

What is the recommended Mitigation?

Organizations using PTC Windchill or FlexPLM should:
• Apply the latest vendor security updates immediately.
• Verify whether systems are internet accessible and restrict external exposure where possible.
• Hunt for JSP web shells within the /Windchill/login/ directory.
• Review logs for suspicious requests targeting Windchill login endpoints.
• Rotate credentials and perform a full compromise assessment if exploitation is suspected.

What FortiGuard Coverage is available?

• FortiGuard IPS Service helps detect and block exploitation attempts targeting vulnerable PTC Windchill PDMlink and FlexPLM servers before attackers can gain remote code execution. Intrusion Prevention | FortiGuard Labs
• FortiGuard Antivirus & Behavior Detection Service identifies and blocks malicious payloads and suspicious post-exploitation behavior associated with Cl0p intrusion activity.
• FortiGuard Web Filtering Service prevents access to known malicious domains, command-and-control (C2) infrastructure, and phishing sites used during the attack lifecycle.
• FortiGuard IOC Service provides up-to-date indicators of compromise (IOCs), enabling security teams to identify affected systems, detect attacker activity, and accelerate threat hunting.
• FortiGuard Incident Response Service assists organizations with incident investigation, containment, forensic analysis, eradication of attacker persistence, and recovery following a confirmed compromise.

What is the Vulnerability?

FortiGuard telemetry shows continued exploitation attempts targeting vulnerable Joomla SP Page Builder installations. CVE-2026-48908 is a critical unauthenticated remote code execution (RCE) vulnerability affecting the SP Page Builder extension for Joomla. The flaw allows attackers to upload arbitrary PHP files through the custom icon upload functionality without authentication, potentially enabling remote code execution and full server compromise.

Public proof-of-concept (PoC) exploit code is available, and active exploitation has been observed. The sustained increase in weekly exploitation activity indicates ongoing automated scanning campaigns targeting Internet-facing Joomla servers, highlighting the need for immediate patching and monitoring of vulnerable deployments.

What is the recommended Mitigation?

• Upgrade SP Page Builder to version 6.6.2 or later.
• Restrict public access to Joomla administrative interfaces.
• Prevent PHP execution from upload/media directories.
• Monitor for unexpected PHP files and newly created administrator accounts.
• Review web server logs for suspicious POST requests targeting the SP Page Builder upload endpoint.

What FortiGuard Coverage is available?

• FortiGuard Intrusion Prevention System (IPS) protects against exploitation attempts targeting vulnerable SP Page Builder deployments. Intrusion Prevention | FortiGuard Labs
• FortiGuard Web Filtering blocks access to known malicious domains, command-and-control infrastructure, and payload hosting locations associated with post-exploitation activity.
• FortiGuard Antivirus detects and blocks malicious payloads, web shells, backdoors, and other malware that attackers may deploy after successfully exploiting vulnerable Joomla installations.
• FortiEDR detects suspicious post-exploitation activities, including unauthorized command execution, web shell execution, persistence attempts, credential theft, and lateral movement from compromised Joomla servers.
• FortiGuard Incident Response Service helps organizations investigate suspected compromises, identify attacker activity, determine the scope of impact, and support containment, remediation, and recovery efforts following exploitation.

What is the Vulnerability?

Multiple critical vulnerabilities affecting Ubiquiti UniFi OS can be chained together to achieve unauthenticated remote code execution (RCE) with root privileges. The vulnerabilities include CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which together bypass authentication, access protected resources, and execute arbitrary operating system commands.

The vulnerabilities impact UniFi OS deployments used to manage enterprise networking infrastructure, including gateways, network controllers, video surveillance, and access control systems. Researchers have publicly demonstrated the exploit chain, and the vulnerabilities have been confirmed as actively exploited in the wild. Organizations should immediately upgrade affected systems and restrict management interfaces from Internet exposure.

Successful exploitation could allow attackers to:
• Obtain root-level remote code execution.
• Completely compromise UniFi OS devices.
• Steal administrative credentials and configuration data.
• Modify firewall, VPN, and network settings.
• Deploy malware or ransomware.
• Pivot into internal enterprise networks.

What is the recommended Mitigation?

Organizations should:

• Immediately upgrade to the latest patched UniFi OS release.
• Restrict UniFi management interfaces to trusted administrative networks.
• Avoid exposing UniFi OS management portals directly to the Internet.
• Monitor logs for suspicious authentication attempts and command execution.
• Review systems for indicators of compromise if Internet exposure existed prior to patching.
• Apply network segmentation and least-privilege administrative access.

What FortiGuard Coverage is available?

• FortiGuard Intrusion Prevention System (IPS) protects against exploit attempts. Intrusion Prevention | FortiGuard Labs
• FortiGuard Web Filtering blocks access to known malicious infrastructure used to host payloads or support post-exploitation command-and-control activity.
• FortiGuard Antivirus detects and blocks malware payloads, web shells, and other malicious files delivered following successful exploitation.
• FortiEDR detects suspicious post-exploitation behavior, including unauthorized command execution, persistence mechanisms, privilege abuse, and lateral movement originating from compromised systems.
• FortiGuard Incident Response Service assists organizations in investigating potential compromise, determining the scope of attacker activity, and supporting containment, remediation, and recovery efforts following exploitation.

What is the Vulnerability?

FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical details and proof-of-concept (PoC) exploit code.

CVE-2026-10520 is a critical vulnerability affecting Ivanti Sentry that allows remote, unauthenticated attackers to execute arbitrary operating system commands with root privileges. The flaw stems from improper handling of internal configuration commands exposed through an externally accessible API, enabling complete device compromise without valid credentials.

Shortly after disclosure, watchTowr published a detailed technical analysis and public PoC, significantly lowering the barrier to exploitation and increasing the likelihood of opportunistic attacks.

Ivanti Sentry is an enterprise mobile gateway that provides secure access to corporate email, applications, and content for managed mobile devices. Organizations with internet-exposed Ivanti Sentry appliances should prioritize patching immediately, as attackers are actively attempting to exploit vulnerable systems.

What is the recommended Mitigation?

Affected:
Ivanti Sentry 10.5.1 and earlier
Ivanti Sentry 10.6.1 and earlier
Ivanti Sentry 10.7.0 and earlier

Fixed:
10.5.2
10.6.2
10.7.1

Recommended Actions
• Immediately upgrade to Ivanti Sentry 10.5.2, 10.6.2, or 10.7.1.
• Assume internet-exposed, unpatched appliances may already be compromised.
• Review administrative accounts for unauthorized additions.
• Search for web shells, persistence mechanisms, and suspicious root-level processes.
• Rotate credentials and invalidate tokens if compromise is suspected.
• Monitor for exploitation attempts and anomalous outbound connections.
• Enable IPS protections and virtual patching while emergency updates are being deployed.

What FortiGuard Coverage is available?

• FortiGuard IPS protects against exploit attempts targeting vulnerable Ivanti Sentry appliances. Intrusion Prevention | FortiGuard Labs
• FortiGuard Web Filtering blocks access to known malicious infrastructure used to host payloads or support post-exploitation command-and-control activity.
• FortiGuard AntiVirus detects and blocks malware payloads, web shells, and other malicious files delivered following successful exploitation.
• FortiEDR detects suspicious post-exploitation behavior, including unauthorized command execution, persistence mechanisms, privilege abuse, and lateral movement originating from compromised systems.
• FortiGuard Incident Response Service assists organizations in investigating potential compromise, determining the scope of attacker activity, and supporting containment, remediation, and recovery efforts following exploitation.

What is the Attack?

A critical authentication bypass vulnerability, CVE-2026-20253 (CVSS 9.8), affects Splunk Enterprise versions 10.0.x and 10.2.x. The flaw stems from missing authentication on a PostgreSQL sidecar service endpoint, allowing an unauthenticated attacker to create or truncate arbitrary files on a vulnerable server.

Security researchers have demonstrated that the vulnerability can be leveraged toward pre-authentication remote code execution (RCE) under certain conditions, and active exploitation has been confirmed. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, making it a high-priority patching target for organizations running exposed Splunk Enterprise instances.

An attacker who successfully exploits CVE-2026-20253 may be able to:
• Create or truncate arbitrary files on the target server.
• Bypass authentication protections.
• Potentially achieve pre-authentication remote code execution.
• Disrupt Splunk services.

What is the recommended Mitigation?

Affected:
Splunk Enterprise 10.2 prior to 10.2.4
Splunk Enterprise 10.0 prior to 10.0.7

Upgrade to:
Splunk Enterprise 10.2.4 or later
Splunk Enterprise 10.0.7 or later

If immediate patching is not possible:
• Disable the PostgreSQL sidecar service as recommended by Splunk.
• Restrict network access to Splunk management interfaces.
• Monitor for unexpected file creation or service behavior.
• Review logs for suspicious unauthenticated access attempts.

What FortiGuard Coverage is available?

• FortiGuard IPS provides protection against exploit attempts targeting vulnerable services.
• FortiGuard Web Filtering blocks access to known malicious infrastructure used during exploitation.
• FortiGuard AntiVirus detects and blocks malware payloads delivered following successful exploitation.
• FortiEDR detects suspicious post-exploitation behavior, including unauthorized file modifications and persistence techniques.
• FortiGuard Incident Response Service assists organizations in investigating and determining the scope of compromise, and supporting remediation efforts following exploitation.

What is the Attack?

Google Threat Intelligence Group (GTIG) and Mandiant have identified an active compromise and extortion campaign attributed to ShinyHunters (tracked as UNC6240) targeting Oracle PeopleSoft environments. The attackers exploited a previously unknown remote code execution vulnerability, CVE-2026-35273, before Oracle released an advisory and patches, making this a true zero-day attack. The campaign primarily targeted higher education institutions, with approximately 68% of identified victims belonging to the education sector.

Organizations running internet-accessible Oracle PeopleSoft Environment Management components are at highest risk. Successful exploitation enables unauthenticated remote code execution, deployment of remote management tooling, data theft, and extortion activities.

An attacker who successfully exploits CVE-2026-35273 can:
• Execute arbitrary code on vulnerable Oracle PeopleSoft servers.
• Establish persistent remote access using legitimate administration tools.
• Conduct reconnaissance of enterprise infrastructure and configurations.
• Move laterally within the environment.
• Steal sensitive employee, student, financial, and operational data.
• Conduct extortion or ransomware-style operations using stolen data.

What is the recommended Mitigation?

Potentially exposed systems include:
Internet-facing Oracle PeopleSoft deployments.

• Immediately apply Oracle's security updates for CVE-2026-35273.
• Restrict external access to PeopleSoft Environment Management services.
• Review logs for suspicious activity between May 27 and June 9, 2026.
• Hunt for unauthorized MeshCentral agents and remote management tools.
• Monitor for unusual administrative activity, data access, and large outbound transfers.
• Conduct compromise assessments on exposed PeopleSoft systems.

What FortiGuard Coverage is available?

• FortiGuard IPS: Detects and blocks exploitation attempts targeting Oracle PeopleSoft vulnerabilities. Intrusion Prevention | FortiGuard Labs
• FortiGuard Web Filtering: Blocks access to known malicious infrastructure and command-and-control domains.
• FortiGuard AntiVirus and Behavior-Based Detection: Detects Mesh-Central-based payloads and malicious post-exploitation activity.
• FortiEDR and FortiXDR: Identify suspicious remote administration activity, persistence mechanisms, and lateral movement behavior.
• FortiSIEM and FortiAnalyzer: Provide visibility into exploitation attempts and post-compromise activity across the environment.

طراحی سایت : رادکام