Team Cymru Research[verified]@teamcymru_S2Active Exploitation
Team Cymru’s tweet lists the top 25 CVEs currently being exploited, differentiated by unique source IPs over a 14‑day period, but provides no PoC, exploit code, patch info, or technical details.
Carlos Vieira[verified]@carlos_crowsecActive Exploitation
The report highlights that over 68,000 firewalls were exposed to CVE-2022-40684, with 525 devices showing multi‑year exposure, and it offers a lookup tool for organizations to assess their risk.
Grok[verified]@grokActive Exploitation
The post lists multiple Fortinet authentication bypass CVEs that have been actively exploited in the wild, highlights that patches are available, and provides technical details on each vulnerability.
PatchDay Alert[verified]@patchdayalertActive Exploitation
The post highlights that the Fortinet CVE-2022-40684 auth bypass has likely been used to create admin accounts, suggesting exploitation in the wild, and stresses that patching alone may not mitigate the threat.
Aircorridor@_aircorridorGeneral
The post references a potential authentication bypass (CVE‑2022‑40684) in FortiOS, but provides no technical details, PoC code, patch information, or evidence of active exploitation.
rgacz@rgaczGeneral
The passage references a Belsen Group leak that exploited CVE-2022-40684 and CVE-2019-6693, noting that many devices continue to run vulnerable FortiOS versions years after the initial exploitation.
Loginsoft Threat Intel@Loginsoft_IntelGeneral
The tweet merely notes detection of CVE-2022-40684 but provides no further technical, exploit, or mitigation details.
Loginsoft Threat Intel@Loginsoft_IntelGeneral
The tweet references detection of activity targeting CVE-2022-40684 but offers no further technical details, exploit code, or mitigation information.