Multiple hackers around central screen displaying code with falling shields, spider, locks, and warnings

Daily Dose of Cybersecurity News - August 14, 2025

Critical Pre-Auth RCE Vulnerability in FortiSIEM (CVE-2025-25256)

Critical

What happened

Fortinet disclosed a critical vulnerability (CVE-2025-25256) in FortiSIEM, allowing unauthenticated attackers to execute arbitrary code via crafted CLI requests. Exploit code for this flaw has been observed in the wild.

Who is affected

Organizations using FortiSIEM versions 5.4 through 7.3 are impacted, including governments, large enterprises, financial institutions, healthcare providers, and managed security service providers (MSSPs).

Why it matters

This vulnerability enables remote code execution without authentication, potentially leading to full system compromise. Given FortiSIEM's role in security operations, exploitation could have severe consequences for affected organizations.

How it could have been prevented

Regularly updating FortiSIEM to the latest versions and applying security patches promptly can mitigate such vulnerabilities. Implementing strict access controls and monitoring for unusual activity are also recommended.

Relevant professional terms

Remote Code Execution (RCE)
A type of vulnerability that allows an attacker to run arbitrary code on a target system remotely.
Security Information and Event Management (SIEM)
A system that aggregates and analyzes security data from various sources to detect and respond to threats.

Recommended reading: Fortinet Security Advisory FG-IR-23-135

New Downgrade Attack Bypasses FIDO Authentication in Microsoft Entra ID

High

What happened

Security researchers have identified a downgrade attack targeting Microsoft Entra ID, where attackers trick users into authenticating via weaker methods instead of FIDO-based authentication, making them susceptible to phishing and session hijacking.

Who is affected

Organizations utilizing Microsoft Entra ID with FIDO authentication are at risk, especially those that allow fallback to less secure authentication methods.

Why it matters

This attack undermines the security benefits of FIDO authentication by coercing users into using less secure methods, thereby exposing accounts to phishing attacks and unauthorized access.

How it could have been prevented

Enforce strict authentication policies that disallow fallback to weaker methods and ensure that FIDO authentication is the sole method permitted for user verification.

Relevant professional terms

FIDO Authentication
A set of standards developed to provide secure and passwordless authentication methods using public key cryptography.
Downgrade Attack
A type of attack where a system is tricked into using a less secure mode of operation, making it vulnerable to exploitation.

Recommended reading: How attackers are still phishing "phishing-resistant" authentication

Surge in Fortinet VPN Brute-Force Attacks Raises Zero-Day Concerns

High

What happened

A significant increase in brute-force attacks targeting Fortinet SSL VPNs was observed in early August 2025, with attackers later shifting focus to FortiManager systems. This pattern has historically preceded the disclosure of new vulnerabilities.

Who is affected

Organizations utilizing Fortinet SSL VPN and FortiManager systems are at risk of unauthorized access due to these attacks.

Why it matters

The coordinated nature and timing of these attacks suggest potential exploitation of unknown vulnerabilities (zero-days), posing significant security risks to affected organizations.

How it could have been prevented

Implementing strong, unique passwords and multi-factor authentication (MFA) for VPN access can mitigate brute-force attacks. Regularly monitoring and restricting access to management interfaces can also reduce exposure.

Relevant professional terms

Brute-Force Attack
An attempt to gain unauthorized access by systematically trying all possible password combinations.
Zero-Day Vulnerability
A software flaw unknown to the vendor, leaving systems vulnerable until a fix is developed.

Recommended reading: Fortinet warns of auth bypass zero-day exploited to hijack firewalls

Cyberattack Disrupts Pennsylvania Attorney General's Office Operations

High

What happened

The Pennsylvania Attorney General's Office experienced a cyberattack that disrupted its website, email accounts, and landline phone systems. Efforts are underway to investigate the incident and restore services.

Who is affected

The Office of the Pennsylvania Attorney General and its staff are directly impacted, with potential indirect effects on the public relying on their services.

Why it matters

This incident highlights the vulnerability of critical government infrastructure to cyber threats, potentially hindering essential legal and administrative functions.

How it could have been prevented

Implementing robust cybersecurity measures, including regular system updates, network monitoring, and employee training on phishing and other cyber threats, could mitigate such incidents.

Relevant professional terms

Ransomware
A type of malicious software designed to block access to a computer system until a sum of money is paid.
Denial-of-Service (DoS) Attack
A cyberattack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services.

Recommended reading: therecord.media

North Korean APT37 Deploys Multifaceted Malware Campaign Against South Korean Targets

High

What happened

A North Korean threat group, identified as ChinopuNK-a subgroup of APT37 (Scarcruft)-launched a cyberattack campaign against South Korean entities. The attackers utilized phishing emails disguised as postal code update notices to deliver a suite of malware, including the NubSpy backdoor, FadeStealer infostealer, LightPeek PowerShell stealer, and the VCD ransomware.

Who is affected

South Korean organizations and individuals targeted by the phishing campaign.

Why it matters

This campaign signifies a strategic shift by North Korean APT groups from traditional espionage to incorporating ransomware for financial gain and psychological pressure. The use of multiple malware types enhances the attack's effectiveness and persistence, posing a significant threat to targeted entities.

How it could have been prevented

Implementing comprehensive email filtering to detect and block phishing attempts, conducting regular security awareness training for employees, and maintaining up-to-date endpoint protection can mitigate the risk of such attacks.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information or downloading malicious software.
Backdoor
A type of malware that allows unauthorized access to a system, enabling attackers to control the system remotely without the user's knowledge.

Recommended reading: North Korean State Actors Deploy Surgical Ransomware in Ongoing Cyberattacks on US Healthcare Orgs