DiscoverSANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix
SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix

SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix

Update: 2025-11-17
Share

Description



Fortiweb Vulnerability

Fortinet, with significant delay, acknowledged a recently patched vulnerability after exploit attempts were seen publicly.

https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486

https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/

https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com

Flnger.exe and ClickFix

Attackers started to use the finger.exe binary to retrieve additional payload in ClickFix attacks

https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492
Comments 
loading
In Channel
loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix

SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix

Dr. Johannes B. Ullrich