Thursday, July 24, 2025
Sophos Firewall: Verify if the hotfixes for CVE-2025-6704 CVE-2025-7624, CVE-2025-7382, CVE-2024-13974, and CVE-2024-13973 have been applied
RSS Feed for Security
Microsoft Security Respond Centre
FortiGuard Outbreak Alerts will be the mechanism for communicating important information to customers and partners. When a cybersecurity incident/attack/event occurs that has large ramifications to the cybersecurity industry and affects numerous organizations, this page will be updated with a link to the individual FortiGuard Outbreak Alert.
https://filestore.fortinet.com/fortiguard/rss/outbreakalert.xml
For more Fortinet RSS:
https://www.fortiguard.com/rss-feeds
Another RSS feed with list of cybersecurity feed:
GitHub - thehappydinoa/awesome-threat-intel-rss: A curated list of Awesome Threat Intelligence blogs
RSS Feed for Security
Tuesday, July 15, 2025
A Simple Linux. A Complete SIEM
You can download it for your test GitHub - eddiechu/Terminal-SIEM: Super light, super fast, unlimited search idea
Reference:
A Simple Linux. A Complete SIEM
TencentOS Server V4正式获OpenSCAP官方支持,安全合规能力全面升级
TencentOS Server V4通过社区提案、代码适配和多轮测试,已正式列入 OpenSCAP 官方支持发行版列表
包含185条安全规则的基础版(basic)安全基线为例进行扫描,用户也可自行选择包含313条安全规则的标准版(standard)安全基线
https://mp.weixin.qq.com/s/yDN7wTouvY4GeuSnIg4G9Q
TencentOS Server V4正式获OpenSCAP官方支持,安全合规能力全面升级
Monday, June 16, 2025
Windows SMB Client Elevation of Privilege Vulnerability - CVE-2025-33073 - actively exploited in the wild
- SMB coercion must be possible
- SMB signing must not be strictly enforced on the target system
Windows SMB Client Elevation of Privilege Vulnerability - CVE-2025-33073 - actively exploited in the wild
Wednesday, June 11, 2025
Azure AD Connect 2.0 change proxy setting
1. Go to the program files -> Microsoft Azure Active Directory Connect -> To modify the file proxy config in the file "Microsoft.ApplicationProxy.Connector.Common.dll.config
2. Netsh winhttp set proxy "<proxy IP>"
3. Restart the service "Microsoft Azure AD Sync"
Then, you can run the powershell command >Start-ADSyncSyncCycle -PolicyType Initial
To use the new proxy for the sync.
Azure AD Connect 2.0 change proxy setting
Fortinet SSL VPN customers need to be aware - Gradually transition to ZTNA while maintaining operational stability
- FortiOS 7.0+ integrates ZTNA with FortiClient agents, FortiAuthenticator, and FortiOS application gateways for granular access control.
- ZTNA aligns with hybrid cloud and SaaS environments, reducing attack surfaces compared to SSL VPN's "trusted perimeter" (Trust, but verify) model.
- Enhanced Security : ZTNA enforces "never trust, always verify," mitigating lateral movement risks from compromised endpoints or outdated SSL configurations.
- Performance Gains : ZTNA leverages SASE architecture, enabling low-latency, distributed access without complex tunnel management.
- Stay on 7.4.x (Please make sure you have hardening your SSL VPN) (Reference: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Hardening-FortiGate-SSL-VPN-Best-Practices-for/ta-p/349193 and https://www.andrewtravis.com/blog/2024/09/30/fortigate-ssl-vpn-hardening)
- Switch to IPSec VPN if go for 7.6
- ZTNA
- Stay on IPSec VPN (There may hit operational issue since some public Internet may block IPSec)
Fortinet SSL VPN customers need to be aware - Gradually transition to ZTNA while maintaining operational stability