Skip to content
  Thursday 15 January 2026
Trending
April 29, 2025<h3>CISOs Turn to Consolidation: A Strategic Shift</h3> August 15, 2023Data Center Security at Risk: CyberPower and Dataprobe Products Reveal Numerous Vulnerabilities June 11, 20255 Must-Know River Island Tips! May 27, 2025<h3>Beware: Fake AI Tools Fuel a Year-Long Malware Attack!</h3> January 22, 2025Unlocking the Hybrid Cloud: A Quick Glossary | TechRepublic May 14, 2025<h3>RFK Jr Taps AI to Revolutionize Cybersecurity and Health IT at Federal Agencies</h3><br /> <br /> In a bold move to strengthen the United States’ technological infrastructure, RFK Jr. is set to harness the power of artificial intelligence to enhance cybersecurity and health IT across federal agencies. This initiative aims to address the increasing sophistication of cyber threats and improve the efficiency of health information systems, ensuring that both sectors are equipped to meet 21st-century challenges.<br /> <br /> The integration of AI is expected to bring about transformative changes in how agencies handle sensitive data and respond to cyber incidents. By leveraging advanced machine learning algorithms, AI can detect and neutralize threats more swiftly and accurately than traditional methods, ultimately safeguarding critical government networks and information.<br /> <br /> Beyond cybersecurity, AI’s potential in health IT is vast, offering opportunities to streamline patient data management, improve diagnostic accuracy, and personalize treatment plans. The deployment of AI tools in healthcare settings within federal agencies could lead to significant improvements in service delivery and patient outcomes.<br /> <br /> RFK Jr.’s strategy reflects a growing recognition of AI’s role in modern governance, as agencies worldwide increasingly adopt these technologies to enhance operational efficiency and resilience. By prioritizing AI development and implementation, this initiative not only aims to protect vital systems but also to position the U.S. as a leader in technological innovation and security.<br /> <br /> As this ambitious plan unfolds, stakeholders and policymakers will be closely watching its impact on the nation’s cyber and health IT landscapes. The successful integration of AI into these sectors could serve as a model for future innovations, paving the way for a more secure and technologically advanced government. April 7, 2025<h3>FedRAMP’s Automation Breakthrough: Big Promises Ahead!</h3> January 23, 2025<h3>Fortifying the Digital Frontline: Strategic Defense Tactics for Agencies</h3> October 7, 2024<p><strong>Ukrainian Admits Guilt in Raccoon Stealer Malware Scandal!</strong></p> October 10, 2023Senior Cybersecurity Compliance Leader – Medical Device Product Security
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
  Industry News  Fortinet Warns Hackers Can Still Access FortiGate after Patching using SSL-VPN Symlink Exploit
Industry News

Fortinet Warns Hackers Can Still Access FortiGate after Patching using SSL-VPN Symlink Exploit

SecuredyouadmSecuredyouadm—April 11, 20250
FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail
More stories

RedCurl Cybercrime Group Exploits Windows PCA Tool for Corporate Espionage

March 14, 2024

Discover the Ultimate Vulnerability Prioritization Strategy!

September 29, 2024

Is it Time to Abandon Security Awareness Training?

December 19, 2023

HTTP/2 Vulnerability Exploited by Zero-Day Attacks Targeting ‘Rapid Reset’ Weakness

October 12, 2023



On April 11, 2025, Fortinet disclosed that threat actors have discovered a method to maintain read-only access to vulnerable FortiGate devices even after the initial breach vector was patched. The attackers exploited known security flaws such as CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762. Fortinet explained that the threat actor utilized a known vulnerability to establish read-only access by creating a symbolic link between the user file system and the root file system in a folder serving language files for the SSL-VPN.

The modifications made by the threat actors in the user file system went undetected, allowing the symbolic link to persist even after the initial security vulnerabilities were fixed. This allowed the threat actors to maintain read-only access to files on the device’s file system, including configurations. However, customers who did not enable SSL-VPN were not affected by this issue. Fortinet stated that the activity was not targeted at any specific region or industry and notified affected customers directly.

To prevent similar incidents, Fortinet released software updates for FortiOS versions 7.4, 7.2, 7.0, and 6.4, which automatically remove the malicious symlink flagged by the antivirus engine. Additionally, FortiOS versions 7.6.2, 7.4.7, 7.2.11, 7.0.17, and 6.4.16 removed the symlink and modified the SSL-VPN UI to prevent the serving of such malicious links. Customers are advised to update their instances to the recommended FortiOS versions, review device configurations, and treat all configurations as potentially compromised.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory recommending users to reset exposed credentials and consider disabling SSL-VPN functionality until patches are applied. The Computer Emergency Response Team of France (CERT-FR) acknowledged compromises dating back to early 2023. WatchTowr CEO Benjamin Harris expressed concerns over the incident, emphasizing the increasing speed of exploitation compared to patching and the attackers’ capability to deploy backdoors for persistence even after mitigation measures are taken.



Source link

FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail

Securedyouadm

North Korean IT Experts Target Europe’s Leading Tech Companies

Why This Year’s RSAC Conference is a Must-Attend Event

Related posts
  • Related posts
  • More from author
Industry News

5 Reasons AI-Driven Business Need Dedicated Servers – SmartData Collective

October 14, 20250
Industry News

The Future of Cyberthreat Sharing Post-CISA 2015: What’s Next?

October 1, 20250
Industry News

Meta Strikes $14.2B AI Deal with CoreWeave for Cutting-Edge Infrastructure

October 1, 20250
Load more
Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Read also
Careers

Cybersecurity Analyst

January 14, 20260
Careers

Lead Cybersecurity – SOX

January 14, 20260
Careers

Senior Cloud Security Engineer, AVP – BXTI Cybersecurity

January 14, 20260
Careers

Sr. Cybersecurity Analyst, Compliance

January 14, 20260
Careers

Cybersecurity Analyst

January 14, 20260
Careers

CYBERSECURITY ANLST SR

January 14, 20260
Load more
Stay Social!
192Likes
4,500Followers
13Subscribers
46Followers
Recent posts
  • Cybersecurity Analyst
  • Lead Cybersecurity – SOX
  • Senior Cloud Security Engineer, AVP – BXTI Cybersecurity
  • Sr. Cybersecurity Analyst, Compliance
  • Cybersecurity Analyst

    # TRENDING

    how old is my computerhow old is my dell laptophow old is my HP laptophow old is my laptophow old is my toshiba laptophow to find computer ageverify computer agestar wars theme wallpapersThe Best Hacking Bookswiresharkusb device not found windows 10/11usb device not recognized windows 10/11 errorWhat is AIGPUSnifferuTorrentvulnerability scanner downloadWifi Hacking SoftwareWifi Hacking Appsolved windows 10/11 usb device not recognizedstar wars windows 7 theme downloadTwitter Account Security
    © Copyright Mister Cybersecurity LLC 2023, All Rights Reserved
    • About
    • Contact
    • Privacy
    • ToS
    • Disclosures