InfoSec News Nuggets – 01-29-2026

Fortinet Patches Actively Exploited FortiCloud SSO Zero-Day (CVE-2026-24858) Fortinet has begun releasing security updates to address CVE-2026-24858, a critical zero-day vulnerability that allowed attackers to bypass FortiCloud single sign-on (SSO) authentication and gain administrative access to FortiGate firewalls. The flaw, rated CVSS 9.4, was actively exploited in the wild by two malicious FortiCloud accounts before being blocked on January 22, 2026. Attackers created unauthorized admin accounts and modified VPN configurations on fully patched devices, indicating…
Read More

InfoSec News Nuggets 12/23/2025

Critical n8n RCE vulnerability enables full server compromise A critical remote code execution flaw in the n8n workflow automation platform, tracked as CVE-2025-68613 (CVSS 9.9), allows authenticated users to inject expressions that escape the workflow sandbox and execute arbitrary OS commands on the host server. The issue affects versions from 0.211.0 up to but not including 1.120.4, 1.121.1, and 1.122.0, enabling full instance takeover, data exposure, and lateral movement if unpatched.   Threat Actors Exploit…
Read More