Fortinet admits it found another worrying zero-day being exploited in attacks

TechRadarThursday, November 20, 2025 at 3:03:00 PM
NegativeTechnology
Fortinet admits it found another worrying zero-day being exploited in attacks
  • Fortinet has reported the discovery of a zero-day vulnerability in its FortiWeb web application firewall, which is being actively exploited in attacks, prompting the release of a patch to mitigate the risk.
  • This vulnerability raises significant concerns for Fortinet as it could potentially compromise the security of numerous clients relying on their web application firewall solutions, necessitating immediate action to protect user data.
  • The ongoing emergence of such vulnerabilities highlights a troubling trend in cybersecurity, where both established and new threats continue to challenge organizations, as seen with recent issues in other platforms like Google Chrome and the resurgence of legacy commands in malicious campaigns.
— via World Pulse Now AI Editorial System

Was this article worth reading? Share it

Recommended Readings
Microsoft says Copilot will 'finish your code before you finish your coffee' provoking another barrage of anti-AI and Windows 11 sentiment
NegativeTechnology
Microsoft has announced that its Copilot feature will be able to complete coding tasks quickly, claiming it can 'finish your code before you finish your coffee.' This announcement has led to a wave of negative reactions from Windows 11 users, who have responded with trolling and criticism regarding the AI's capabilities and implications.
Google launches Nano Banana Pro, a massive leap in AI image editing powered by Gemini 3 Pro
PositiveTechnology
Google has launched the Nano Banana Pro, an advanced AI image editing tool built on the Gemini 3 Pro model. This new tool enhances the visualization of information, utilizing Gemini's sophisticated reasoning and real-world knowledge to generate more realistic images than ever before.
WordPress plugin with over a million installs may have a worrying security flaw - here's what we know
NegativeTechnology
A critical flaw in a widely used WordPress plugin, which has over a million installations, has been discovered. This vulnerability allows threat actors to execute arbitrary PHP commands, potentially leading to complete control over affected websites. The issue raises significant concerns regarding the security of WordPress sites and the potential for widespread exploitation.
Bridging the real digital gap in the public sector
NeutralTechnology
Bridging the digital divide in the public sector requires a focus on people rather than solely on technology. This approach emphasizes the importance of human factors in successfully implementing digital solutions within public institutions.
How cloud-based technology is helping contact centers cut carbon emissions
PositiveTechnology
Cloud-based contact centers are significantly reducing carbon emissions while enhancing operational efficiency and sustainability objectives. This technology allows for more flexible and scalable solutions, contributing to a greener approach in customer service operations.
China’s PlushDaemon group uses EdgeStepper implant to infect network devices with SlowStepper malware in global supply-chain attacks
NegativeTechnology
ESET has reported that the Chinese cyber group PlushDaemon is utilizing the EdgeStepper implant to compromise network devices globally with SlowStepper malware. This development highlights the group's capability to launch supply-chain attacks on a worldwide scale.
Malicious free VPN extension makes a comeback
NegativeTechnology
Two malicious extensions named 'Free Unlimited VPN' have been stealing user data for years. Although they were removed in May 2025, a new version has resurfaced on the Chrome Store, raising concerns about user privacy and data security.
Some Spotify fans are still experiencing a major app crashing problem – and there’s still no sign of a fix
NegativeTechnology
Spotify users are facing a significant app crashing issue that has disrupted their music experience for several days. Despite ongoing complaints, there is currently no indication of a fix from the company.