News

Latest news on the subject of B2B cyber security >>> PR agencies: Add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

F5 BIG-IP: BSI warns of highly dangerous vulnerabilities
B2B Cyber ​​Security ShortNews

The BSI has issued a warning about F5 products because they contain several highly dangerous security vulnerabilities that should be closed. The BIG-IP is a network appliance on which most F5 products run. The CVSS 3.1 scores are between 7.5 and 8.8 and are therefore considered highly dangerous. Several vulnerabilities with high CVSS 3.1 scores have been identified in various F5 products. According to the BSI, an attacker could exploit several vulnerabilities in F5 BIG-IP to circumvent security measures, trigger a denial of service, or execute code. CVE-2025-46265 affects F5OS-A and F5OS-C with a score of 8.8 and...

Read more

Hybrid SASE solution FireCloud Internet Access
Hybrid SASE solution FireCloud Internet Access Image: Bing - AI

With FireCloud Internet Access, WatchGuard Technologies presents the first product in a new family of hybrid Secure Access Service Edge (SASE) solutions. This specifically addresses the needs of companies and WatchGuard partners with hybrid IT structures. Thanks to FireCloud, consistent protection can be established across the entire IT sphere, ensuring security even beyond the traditional perimeter with virtually identical configuration – and without additional effort. Hybrid Solutions for On-Premises & Cloud Hybrid IT security environments, in which the use of cloud or firewall-as-a-service products is increasingly becoming important alongside traditional on-premises firewalls, are now part of everyday life…

Read more

SuperBlack Ransomware exploits Fortinet vulnerability
B2B Cyber ​​Security ShortNews

In January 2025, Arctic Wolf Labs reported suspicious activity on Fortinet FortiGate firewall devices. On January 14, Fortinet published confirmation of a zero-day vulnerability affecting FortiOS and FortiProxy products, designated CVE-2024-55591. On February 11, the company confirmed another vulnerability, designated CVE-2025-24472. The new SuperBlack ransomware exploits the latter Fortinet vulnerability to bypass authorization, as recently reported. "Threat actors are always looking for new 'revenue streams,' and the Fortinet vulnerabilities are an example of the risks organizations face from unpatched vulnerabilities. In…

Read more

SonicWall firewall appliance with critical vulnerability
B2B Cyber ​​Security ShortNews

SonicWall has reported a critical 9.8 vulnerability in the SMA1000 appliance. SonicWall has released a corresponding update that should be used immediately. SMA100 appliances are not affected by the vulnerability. SonicWall has discovered a serious security vulnerability (SNWLID-2025-0002) in its SMA1000 network security solutions. This vulnerability could allow attackers to gain unauthorized access to affected systems, which could lead to potential data loss or manipulation. The vulnerability has a critical CVSS score of 9.8 out of 10 and should therefore be addressed immediately. Critical vulnerability - immediately...

Read more

Vulnerability in Fortinet's firewall
B2B Cyber ​​Security ShortNews

A threat research team observed a campaign of suspicious activity on Fortinet FortiGate firewall devices in early December 2024. By gaining access to the management interfaces of the affected firewalls, cybercriminals were able to change the firewall configurations, create new accounts, and log into the SSL VPN portals using these user accounts. In the compromised environments, threat actors were observed using DCSync to extract credentials. While the initial access vector used is not yet confirmed, given the compressed time period in the organizations as well as the affected firmware versions, Arctic Wolf Labs estimates that the exploit of a zero-day vulnerability is very likely…

Read more

Darknet: 15.000 configuration files for FortiGate firewalls
B2B Cyber ​​Security ShortNews

In a darknet forum, the hacker group "Belsen Group" has published over 15.000 unique configuration files from FortiGate firewalls. Although the data is relatively old, it is probably genuine, as security researcher Kevin Beaumont confirms. The data published on the darknet was originally obtained in October 2022 by exploiting the zero-day vulnerability CVE-2022-40684. This configuration and VPN access data comes from more than 15.000 firewalls from the manufacturer Fortinet. The critical vulnerability with the CVSS value 9.6 allowed authentication to be bypassed in the administration interface of Fortinet FortiOS, FortiProxy and FortiSwitchManager. 15.000 data records for firewalls The information published is said to...

Read more

First firewall with BSI BSZ security certificate
B2B Cyber ​​Security ShortNews

The Federal Office for Information Security – BSI for short – has certified the LANCOM R&S®Unified Firewall UF-360 with a security certificate in accordance with the “BSZ” standard, which is also used in critical infrastructures (KRITIS). The German network infrastructure and security supplier LANCOM System is the first company to receive a security certificate in accordance with the “BSZ” test procedure for a firewall. With the “Accelerated Security Certification”, the Federal Office for Information Security (BSI) is addressing, among other things, manufacturers of network components, as these are of outstanding importance for the defense against IT and cyber security risks. The LANCOM R&S®Unified Firewall UF-360 was certified with the…

Read more

Security breaches in Palo Alto Networks firewall devices
B2B Cyber ​​Security ShortNews

On November 18, 2024, Palo Alto Networks announced two vulnerabilities (CVE-2024-0012 and CVE-2024-9474) in Palo Alto Networks OS (PAN-OS), the operating system used on their firewall devices. A day later, watchTowr published a report with technical details on how the two vulnerabilities can be linked together to achieve remote code execution of these vulnerabilities. Just a few hours after the watchTowr report was published, Arctic Wolf Labs observed several attacks affecting Palo Alto Networks devices. Due to the close timing of the watchTowr report and additional evidence reviewed by Arctic Wolf Labs…

Read more

EMA: Cloud Connector for Microsoft 365
EMA: Cloud Connector for Microsoft 365 Image: Bing - AI

For easier connection of the data management and archiving solution EMA to Microsoft 365 Exchange Online and to local Exchange infrastructures, it is now even more secure and user-friendly. The new version of the ARTEC Cloud Connector for Microsoft 365 is now available. The further developed Cloud Connector offers a new web interface that provides an immediate first overview of the current system status with three clearly defined icons, each color-coded according to the status. In addition to the quick overview, the new Cloud Connector can also display more comprehensive information. For example, the last data query by EMA...

Read more

Zyxel firewalls with highly dangerous security vulnerabilities
B2B Cyber ​​Security ShortNews

Zyxel has released 7 patches that fix several vulnerabilities in some firewall versions. Users are advised to install the patches for optimal protection. The vulnerabilities vary from high risk CVSS 8.1 to medium 4.9. Zyxel has released new patches for its firewalls affected by vulnerabilities. According to Zyxel, the following models are affected: Zyxel ATP, USG FLEX and USG FLEX 50(W)/USG20(W)-VPN. The affected products generally still use the firmware ZLD V4.16 to V5.38. For all affected products, there is an update to ZLD V5.39, which closes the gaps. Here are the individual...

Read more