Reports
AI-generated structured vendor updates
Fortinet推出FortiGate 3500G/400G AI防火墙保护混合企业网络
...
英特尔与Fortinet共同开发SP6安全处理器,强化网络防火墙ASIC能力
...
FortiBleed攻击全球暴露约75000台Fortinet防火墙设备
...
Intel与Fortinet战略合作开发SP6安全处理器,18A工艺良率提升至85%
...
Microsoft's Project Perception Automates Vulnerability Remediation with Multi-Model AI Orchestration
In response to competitors like Anthropic and Palo Alto, Microsoft's Project Perception leverages multi-model AI orchestration to automate vulnerability discovery and remediation. This product signifies a transition from manual security operations to autonomous self-healing systems, with control shifting from security analysts to an AI-driven platform.
Microsoft July Patch Tuesday Hits Record 622 CVEs, AI Infrastructure Vulnerabilities Emerge as New Attack Surface
Microsoft's July 2026 Patch Tuesday addresses a record 622 CVEs, including three critical AI vulnerabilities: Copilot RCE (CVSS 9.6), Azure OpenAI EoP (CVSS 9.9), and M365 Copilot EoP (CVSS 9.3). The attack surface expands from OS to AI service infrastructure, signaling an era of AI-driven vulnerability inflation.
FortiBleed Credential Leak Exposes 75K FortiGate Firewalls, Management Plane Security Gaps
The FortiBleed campaign leaked configs from ~75,000 internet-facing FortiGate firewalls, with admin credentials hashed using weak SHA-256 (pre-PBKDF2) easily cracked offline. This highlights risks of exposed management interfaces and inadequate password policies.
CrowdStrike Buys XM Cyber IP: Attack Path Management to Power Predictive Security on Falcon
CrowdStrike acquires all IP assets of XM Cyber (45+ patents and source code) while leaving XM Cyber as an independent licensee. This integrates attack path management into the Falcon platform, shifting from reactive EDR to predictive security, and strengthens partnership with European retail giant Schwarz Digits for market expansion.
Global FortiGate Compromise Exposes Critical Management Plane Vulnerabilities
Pakistan CERT warns of approximately 74,000 Fortinet FortiGate devices compromised across 194 countries. Attackers exploited exposed management interfaces and legacy credential storage. The incident underscores the critical need for securing network edge device management planes.
CrowdStrike Integrates Claude Compliance API, Bringing AI Agent Monitoring into SOC
CrowdStrike integrates Anthropic's Claude Compliance API into its Falcon platform, enabling unified monitoring of Claude AI activities alongside endpoint, identity, and cloud telemetry. This formalizes AI agent security as a standard SOC function, reflecting the industry-wide shift of security budgets towards specialized vendors.
FortiBleed Exposes 70k+ Devices: Attack Surface Shifts from Zero-Day to Credential Hygiene
In July 2026, the FortiBleed credential theft campaign targeted 73,000+ Fortinet devices using a custom sniffer tool. Attackers exploited default/weak passwords, not zero-days, and are linked to INC and Lynx ransomware groups. Global banks, energy firms, and critical infrastructure operators are impacted, exposing a systemic failure in basic security hygiene.
FortiGate Firewalls Breached: 430K Devices Targeted with VPN Credential Sniffing
Attackers compromised approximately 430,000 FortiGate firewalls worldwide, deploying custom sniffers to intercept VPN credentials. The operation is linked to INC Ransom and Lynx ransomware groups, highlighting a new attack surface on edge devices that bypasses traditional EDR/SIEM.
Palo Alto Networks PAN-OS Vulnerabilities: Buffer Overflow and Active Exploitation
Palo Alto Networks disclosed 13 PAN-OS vulnerabilities, with the most critical being CVE-2026-0288 (CVSS 9.2), a buffer overflow in User-ID TSA allowing unauthenticated RCE. CVE-2026-0257, an authentication bypass in GlobalProtect, is actively exploited in the wild.
Fortinet Launches NP7/SP5 Processors and FortiSOC Cloud Platform, Tightening Hardware Lock-in and Operational Control
Fortinet launches FortiGate G-series (3500G/400G) with custom NP7 and SP5 processors, and FortiSOC, a unified cloud-delivered SOC platform consolidating six functions into a single SaaS with AI agents. Q1 revenue hit $1.85B, product revenue up 41%. The move aims to double lock-in via hardware and cloud control plane.
Fortinet FortiAIGate with NVIDIA Shifts AI Security Control to GPU-Accelerated Inline
Fortinet launches FortiAIGate integrating NVIDIA Blackwell GPU and Dynamo inference framework for inline AI workload protection across data center, cloud, and edge. Promises ultra-low latency, multi-tenancy, and data sovereignty compliance.
Cloudflare Embeds Live Threat Intel into WAF, Shifting Control from Manual Rules to Automated Engine
Cloudflare announces integration of real-time threat intelligence (from Cloudforce One) into its WAF engine, enabling proactive rules based on IP, attacker names, target industries, etc. Uses always-on detection with O(1) constant-time lookup for negligible latency. Currently IP-based, with plans for JA3 and domain matching.
Fortinet Hardens AI Security into ASIC with 3500G/400G, Shifting Control to Silicon
Fortinet expands FortiGate G-series with 3500G (400GbE datacenter) and 400G (enterprise edge), natively integrating shadow AI detection and MCP traffic inspection into NP7/SP5 ASICs, shifting AI security from software to silicon for zero-performance-loss security enforcement.
Fortinet Warns of Surging AI-Accelerated Edge Device Attacks with MCP Servers Used for Attack Automation
<p>Fortinet's investigation reveals a rising trend of AI-assisted attacks targeting edge devices. Attackers use MCP servers and AI to automate cyberattacks — requiring only basic network knowledge, they use prompt-based conversational commands to generate attack frameworks, achieving full automation of target identification, password spraying, and vulnerability exploitation. Key IOCs: anomalous admin access from 212[.]11.64.250 or 185[.]196.11.225, unauthorized user accounts (fortiuser, fortinet-support). This marks an inflection point where AI shifts from "defense tool" to "attack weapon."</p>
Fortinet Warns of Surging AI-Accelerated Edge Device Attacks with MCP Servers Used for Attack Automation
<p>Fortinet's investigation reveals a rising trend of AI-assisted attacks targeting edge devices. Attackers use MCP servers and AI to automate cyberattacks — requiring only basic network knowledge, they use prompt-based conversational commands to generate attack frameworks, achieving full automation of target identification, password spraying, and vulnerability exploitation. Key IOCs: anomalous admin access from 212[.]11.64.250 or 185[.]196.11.225, unauthorized user accounts (fortiuser, fortinet-support). This marks an inflection point where AI shifts from "defense tool" to "attack weapon."</p>
Cloudflare GA Post-Quantum IPsec: Hybrid ML-KEM Standard Defeats QKD, Proprietary Suites
Cloudflare announces GA of post-quantum encryption for its IPsec product, implementing hybrid **ML-KEM (FIPS 203)** per **draft-ietf-ipsecme-ikev2-mlkem**. It achieves interoperability with **Cisco IOS XE** and **Fortinet FortiOS 7.6.6+** without special hardware. This extends post-quantum security to site-to-site WAN and explicitly rejects the **QKD** approach.