Skip to content
Lars Hilse – Cyber Incident Response // Cyber Security // Cybercrime // Cyber Terrorism // Cyber Defense

Lars Hilse – Cyber Incident Response // Cyber Security // Cybercrime // Cyber Terrorism // Cyber Defense

Cyber Incident Response // Cyber Security // Cyber Crime // Cyber Terrorism // Cyber Defense

  • ACRAC
  • What I do

Tag: actively exploited vulnerability 2025

Critical Fortinet FortiWeb Zero-Day Actively Exploited Since October – Attackers Creating Admin Accounts

Critical Fortinet FortiWeb Zero-Day Actively Exploited Since October – Attackers Creating Admin Accounts
November 17, 2025November 17, 2025 ~ larshilse ~ Leave a comment

Fortinet's got another critical zero-day on its hands (CVE-2025-64446), and this one's a doozy. Attackers have been exploiting an unauthenticated path traversal flaw in FortiWeb since early October to create admin accounts—complete with cheeky passwords like "AFT3$tH4ck." CVSS 9.8. CISA KEV-listed. Actively exploited. If you're running FortiWeb 8.0.1 or earlier and haven't patched to 8.0.2 yet, drop everything and do it now. Then check your device for unauthorized admin accounts. Full breakdown inside.

About this Blog

These are my opinions on #CyberSecurity, #Cybercrime, #CyberTerrorism, #CyberDefense, et al.

I publish using dictation tools; find a typo? You’re welcome to keep it.

My publications, appearances, projects, etc. can be here on TOR: http://larshilse3xpyawo.onion/ ; if you can’t use TOR, use this link through the clear web: https://larshilse3xpyawo.tor2web.xyz

Contact

Email: [email protected] PGP: 44D5 68A1 32A1 AD87 3E29 2AA2 9B4A 1674 17FF C660

Phone: +49 (0)4835 9513027

Please use my full name in the “To” line with my email address, as this will make your message look less like spam. This will happen automatically if you have me in your address book. If you just type in my email address, I probably won’t see your mail.

Recent Posts

  • RondoDox Botnet Exploiting Critical XWiki Vulnerability to Hijack Servers for Crypto Mining
  • Critical Fortinet FortiWeb Zero-Day Actively Exploited Since October – Attackers Creating Admin Accounts
  • chinese-hackers-weaponize-claude-ai-autonomous-cyberattack
  • From Pranks to Paydirt: The Malware Origin Story
  • The Evolution of a Digital Menace

Archives

  • November 2025
  • June 2025
  • May 2025
  • April 2025
  • December 2022
  • March 2020
  • October 2019
  • June 2019
  • May 2019
  • February 2019
  • November 2018
  • October 2018
  • July 2018

Categories

  • ACRAC (16)
  • Application security (14)
  • ceo fraud (4)
  • corporate risks (4)
  • crytocurrency (1)
  • cyber crime (22)
  • cyber defence (5)
  • cyber security (31)
  • cyber terrorism (4)
  • dark web (5)
  • digital ethics (13)
  • global risks (33)
  • infosec reader questions (6)
  • privacy (13)
  • risk management (42)
  • social engineering (5)
  • Uncategorized (4)
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.

To find out more, including how to control cookies, see here: Cookie Policy
Proudly powered by WordPress ~ Theme: Penscratch 2 by WordPress.com.