logo

Hackers Exploit Fortinet Flaw, Deploy ScreenConnect, Metasploit in New Campaign

ID: 50fddf78-25a5-5b4d-9ec2-1c918c683915

STIX ID: report--50fddf78-25a5-5b4d-9ec2-1c918c683915

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-17

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers observed an active campaign (tracked as Connect:fun) abusing CVE-2023-48788, a critical SQL injection in Fortinet FortiClient EMS (CVSS 9.3), to install ScreenConnect and Metasploit Powerfun via PowerShell, certutil, and msiexec; the activity targeted at least one exposed media company and shows manual, targeted exploitation with C2 communications and shared infrastructure seen by other vendors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.