Fortinet patches serious flaws in SSL VPN and web firewall

Fortinet has fixed several critical flaws affecting its products. Ranging from Remote Code Execution (RCE) to SQL Injection, to Denial of Service (DoS), the vulnerabilities impact the FortiProxy SSL VPN and FortiWeb Web Application Firewall (WAF) products. Numerous advisories published by FortiGuard Labs this month and in January 2021 mention various serious flaws that the company has been Continue Reading

Critical flaw in firewall OS patched by Palo Alto Networks

Palo Alto Networks revealed a major flaw discovered in the operating system (PAN-OS) of all its next-generation firewalls that could let unverified network-based hackers bypass verification. The company’s website says that PAN‑OS is the software that runs all of its next-generation firewalls. “When Security Assertion Markup Language (SAML) authentication is enabled and Continue Reading