A Deeper Look at FortiJump (FortiManager CVE-2024-47575)
Reported exploitedFortiManager Read at Bishop Fox
Below is the opening; the full story is at Bishop Fox.
From Bishop Fox
CVE-2024-47575, also known as FortiJump, recently gained widespread attention after news of in-the-wild exploitation leaked prior to any security advisory. According to Mandiant, a threat actor has been exploiting this vulnerability since at least June 2024. Given the highly sensitive nature of centralized management devices, we decided to take a deeper look.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.