Home/ Blog/ Topics/ Edge & VPN security
Topic

Edge & VPN security

Vulnerabilities in the internet-facing gear attackers hit first: firewalls, VPNs, and load balancers from Fortinet, Citrix, Ivanti, Palo Alto, and more.

Security news

Citrix NetScaler flaw CVE-2026-19490 lets an attacker bypass login on Gateway and AAA servers. Patch now.

A critical NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) lets a remote attacker skip login on Gateway and AAA servers.

Security news

Akira ransomware reboots Windows into Safe Mode to shut off security tools

An Akira ransomware affiliate rebooted a Windows host into Safe Mode to disable EDR, stole the data, then fumbled the encryption.

Security news

Gunra ransomware beats MFA by backdooring the login server, not the user. Patching Fortinet won't evict it.

Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws.

Security news

Cisco ASA and FTD firewalls can be crashed by an unauthenticated attacker (CVE-2026-20349). Patch by Aug 14.

CVE-2026-20349 lets an unauthenticated attacker reload Cisco ASA and FTD firewalls for a denial of service. Exploited now, no workaround. Patch by Aug 14.

Security news

Ivanti Endpoint Manager patch: leaked database passwords, editable session recordings, crashable agents

Ivanti's August 2026 Endpoint Manager advisory fixes three high-severity flaws (CVE-2026-18129, -18127, -18125), all resolved in 2024 SU7.

Security news

An AI agent hit 460 servers on its own, but known CVEs did the breaking

A China-linked operator wired DeepSeek into an autonomous agent that swept 460+ exposed servers.

Deep dive

For this week's most-exploited bugs, the patch was the easy part

This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.

Security news

Attackers can slip past Fortinet's fix and keep reading a hacked firewall's files, CISA warns

CISA added CVE-2025-68686 to its exploited catalog: a bypass of Fortinet's FortiOS symlink fix lets attackers who already breached a FortiGate keep reading its

Security news

A Palo Alto VPN auth bypass is now a Qilin ransomware front door

CVE-2026-0257 lets attackers open a Palo Alto GlobalProtect VPN session with no login, and the Qilin ransomware crew is using it for initial access.

Security news

Inc ransomware used the SonicWall SMA zero-days to steal MFA seeds. Resetting passwords will not evict it.

Rapid7 ties the SonicWall SMA 1000 zero-days to an Inc ransomware actor that stole credentials, sessions, and TOTP seeds. A password reset won't evict it.

Security news

Two SonicWall remote-access zero-days are under attack, and patching alone will not clean the box

SonicWall patched two actively exploited SMA 1000 zero-days, CVE-2026-15409 and CVE-2026-15410.

Security news

Progress tells ShareFile users to shut servers down, and no patch means assume breach

Progress told ShareFile customers to shut down on-premises Storage Zone Controllers over a credible threat.

Security news

We said a password reset wouldn't stop FortiBleed. Now it is deploying ransomware.

FortiBleed harvested 110 million Fortinet credentials. SOCRadar links that access to INC and Lynx ransomware, with 12 encryptions and a Nextcloud zero-day.

Security news

Kemp LoadMaster's quote sanitizer became a pre-auth root RCE, exploited hours after the writeup dropped

Kemp LoadMaster's CVE-2026-8037 gives unauthenticated root through its API and is under active exploitation. Affected versions, the fix, and how to detect it.

Security news

Citrix shipped six NetScaler fixes. One of them isn't done until you change a setting.

Citrix fixed six NetScaler flaws, including a pre-login memory leak and an HTTP/2 Bomb denial of service. One fix needs a config change, not just an upgrade.

Security news

Mistype the password and this Lantronix box runs attacker commands as root. CISA says it is happening now.

CISA flagged CVE-2025-67038 as exploited on June 23. A failed login on a Lantronix EDS5000 serial server runs attacker commands as root.

Security news

Attackers can take over your self-hosted UniFi controller with no password. CISA says it is happening now.

Three chained UniFi OS Server flaws give unauthenticated root. CISA added all three to its exploited list on June 23. Patch to 5.0.8 and check who can reach it.

Security news

Your Fortinet password reset won't lock the FortiBleed attacker out

CISA warned Fortinet users on June 18; reporting counted 86,644 affected devices. Resetting passwords is not enough: kill live sessions and fix the hashing.

Security news

INC ransomware never used a zero-day. It used your patch backlog.

INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.

Security news

Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.

CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.

Security news

FortiBleed isn't a Fortinet bug. It's every password you never rotated.

FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.

Security news

FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In

Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.

Security news

Ivanti Sentry's CVE-2026-10520: patch the gateway, then hunt for the breach

Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA's new 3-day patch rule applies; patched gateways were already breached.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.