Attackers are reportedly registering rogue FortiGates into FortiManager, stealing digital certificates and infiltrating customer networks. Based on evidence, China-state hackers have been using this vulnerability since early this year. Over 60,000 connections are vulnerable to this situation due to their exposure on the Internet. The company’s support portal was down at the time of this report, making it harder for customers and defenders to rectify the situation.

SANS Stormcast Monday, November 3rd, 2025: Port 8530/8531 Scans; BADCANDY Webshells; Open VSX Security Improvements
Scans for WSUS: Port 8530/8531 TCP, CVE-2025-59287 We did observe an increase in scans for TCP ports 8530 and 8531. These ports are associated with

