WTF Fortinet?

Their FortiGuard service communication (sending customer behaviour metadata to the cloud to get back threat ratings) was encrypted with a static key, used over several products. A MITM with knowledge of that key could collect data or inject responses.

Fortinet was notified in May 2018 and released the advisory now 🤯

Everything is fine in the wold...

