Hackers Exploit Fortinet Flaw, Deploy ScreenConnect, Metasploit in New Campaign
ID: 50fddf78-25a5-5b4d-9ec2-1c918c683915
STIX ID: report--50fddf78-25a5-5b4d-9ec2-1c918c683915
Feed Name: The Hacker News
Threat Score
Cybersecurity researchers observed an active campaign (tracked as Connect:fun) abusing CVE-2023-48788, a critical SQL injection in Fortinet FortiClient EMS (CVSS 9.3), to install ScreenConnect and Metasploit Powerfun via PowerShell, certutil, and msiexec; the activity targeted at least one exposed media company and shows manual, targeted exploitation with C2 communications and shared infrastructure seen by other vendors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
