Alerts and Advisories

ADVISORY

FortiBleed - Analysis of Reported Credential Compromise of FortiGate Devices

22/06/2026 03:01 PM
CVE-2025-59718 & CVE-2025-59719
CRITICAL SEVERITY

Fortinet is aware of reports of malicious cyber actors targeting Fortinet devices in a credential-harvesting campaign referred to as FortiBleed. Based on our initial analysis, we believe the activity involves threat actors reusing credentials from previous incidents (FG-IR-26-060, FG-IR-25-647) and employing brute-force techniques (as described in a March blog, “Attacks at the Speed of AI”) against devices with weak password hygiene and no multi-factor authentication (MFA).

Read more
ALERT

ClickFix distributing Vidar Stealer via WordPress

13/05/2026 01:41 PM
CRITICAL SEVERITY

The Fiji CERT with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) has observed ClickFix associated activity leveraging WordPress hosted infrastructure to distribute the Vidar Stealer malware. This activity is targeting Australian infrastructure and organisations across multiple sectors. The campaign uses compromised WordPress websites to redirect victims to malware delivery mechanisms. This advisory provides an overview of the activity, an assessment of the threat, observed indicators, detections and recommended mitigations.

Read more
ALERT

Active exploitation of cPanel/WHM critical vulnerability

12/05/2026 01:36 PM
CVE-2026-41940
CRITICAL SEVERITY

This alert is relevant to all Fijian organisations that utilise cPanel/ WebHost Manager (WHM). This alert is intended for a technical audience. Fiji CERT is aware of active exploitation in the region of a critical vulnerability (CVE-2026-41940) affecting cPanel/WHM products. The vulnerability is an authentication bypass, which can allow unauthenticated remote attackers to gain access to the control panel, as well as conduct remote code execution (RCE). The vulnerability affects all versions after 11.40 (which was released in 2013). Patches have been released as of 30 April 2026. Fiji CERT does not have information to indicate that a specific industry or sector is being targeted, however it is noted that products managed by several Managed Service Providers have been impacted, resulting in the compromise of their customers.

Read more
ALERT

Defending Against China-Nexus Covert Networks of Compromised Devices

29/04/2026 08:41 AM
CRITICAL SEVERITY

All Critical Infrastructure operators, Government agencies, and private sector organisations to strengthen monitoring and defensive measures against covert networks of compromised devices linked to advanced China-nexus threat actors.

Read more
ALERT

Cisco Catalyst SD-WAN Vulnerabilities

17/03/2026 08:25 AM
CVE-2026-20129 CVE-2026-20133 CVE-2026-20122
CRITICAL SEVERITY

A flaw in Cisco Catalyst SD-WAN Manager’s API authentication could let a remote attacker gain **netadmin-level access** by sending crafted requests, potentially allowing full control of the system.

Read more
ALERT

SQL Server Elevation of Privilege Vulnerability

16/03/2026 11:14 AM
CVE-2026-21262
HIGH SEVERITY

An authorized user can exploit improper access control in SQL Server to gain elevated privileges over the network.

Read more

What Are Cybersecurity Threats?

Cybersecurity threats are malicious acts that seek to damage data, steal data, or disrupt digital life in general. These threats can target individuals, businesses, or governments and may result in financial loss, privacy violations, operational disruptions, or reputational damage.

Common Types of Cybersecurity Threats

Unauthorized Access

Unauthorized Access/Infiltration: Break-ins due to weak credentials or security flaws, allowing intruders access.

Example: Hackers using stolen passwords to log into internal systems.
Prevention:
  • Enable Multi-Factor Authentication (MFA)
  • Strong password policies
  • Regular security audits
Exploitation of Vulnerabilities

Exploitation of Vulnerabilities: Attacks leveraging unpatched or zero-day vulnerabilities in software or hardware.

Example: Exploiting outdated server software to gain unauthorized access.
  • Apply patches promptly
  • Regular vulnerability scanning
  • Intrusion detection systems
Denial of Service (DoS/DDoS)

Denial of Service (DoS) and Distributed Denial of Service (DDoS): overwhelming a service with traffic, sometimes impacting availability.

Example: Botnet flooding a website causing downtime.
  • Use CDN protection
  • Firewall configuration
  • Traffic filtering
Insider Threats

Insider Threats: Malicious or negligent actions by trusted insiders compromising security.

Example: Employee leaking confidential company data.
  • Role-based access control
  • Employee security training
  • Activity monitoring
Phishing

Phishing: deceptive messaging designed to elicit users’ sensitive information (such as banking logins or business login credentials) or used to execute malicious code to enable remote access.

Example: Fake bank email asking for login credentials.
  • Verify sender
  • Avoid suspicious links
  • Email filtering systems
Ransomware

Ransomware: a tool used to lock or encrypt victims’ files until a ransom is paid.

Example: Hospital records encrypted demanding payment.
  • Regular backups
  • Install updates
  • Endpoint protection software
Social Engineering

Social Engineering: Manipulative tactics (pretexting, baiting) used to deceive individuals into revealing confidential information.

Example: Fake IT support call requesting passwords.
  • Security awareness training
  • Strict verification procedures
  • Clear reporting channels
Malware

Malware: a Trojan, virus, worm, or any other malicious software that can harm a computer system or network.

Example: Trojan hidden in a downloaded attachment infecting a system.
  • Install antivirus software
  • Avoid unknown downloads
  • Keep systems updated
Zero-Day Exploits

Zero-Day Exploits: Attacks exploiting previously unknown vulnerabilities before they can be patched.

Example: Browser vulnerability exploited before security fix release.
  • Advanced threat detection
  • Network segmentation
  • Defense in depth strategy
Supply Chain Attacks

Supply Chain Attacks: Compromises in third-party vendors or software that impact the primary organization.

Example: Malicious code inserted into trusted software update.
  • Vendor risk assessments
  • Software integrity validation
  • Strict third-party access control
Data Breach

Data breach: unauthorised access and disclosure of information.

Example: Customer personal data exposed due to misconfigured database.
  • Encrypt sensitive data
  • Access control management
  • Regular security audits