Fortra® Security & Trust Center

Security Advisory

Denial of Service in CLFS.sys

This vulnerability is caused by CWE‑159: Improper Handling of Invalid Use of Special Elements, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger a system crash. Microsoft silently fixed this vulnerability in the September 2025 cumulative update for Windows 11 2024 LTSC and...
Blog

BEC Global Insight Report: January 2026

Executive SummaryThe findings in this report come from the results of active defense engagements with BEC threat actors. Every month, Fortra Intelligence & Research Experts (FIRE) conducts hundreds of these engagements to collect comprehensive intelligence about BEC tactics and trends to help better understand how the BEC threat landscape is evolving. The primary findings for January 2026...
Blog

What Can the AI Work Caricature Trend Teach Us About the Risks of Shadow AI?

The viral AI work caricature trend on Instagram is prompting users to generate job‑based AI images, unintentionally exposing sensitive personal and professional information. This activity highlights how easily threat actors can identify potential targets, exploit publicly shared details, and attempt LLM account takeovers or prompt‑based data extraction. The trend underscores broader risks of shadow AI, including the leakage of proprietary or sensitive data when employees use public LLMs. Organizations are encouraged to strengthen AI governance, monitor for compromised credentials, and deploy data‑security tools to prevent unauthorized access and disclosure.
Blog

February 2026 Patch Tuesday Analysis

Today’s Patch Tuesday Alert addresses Microsoft’s February 2026 Security Updates. The FIRE team is actively working on coverage for these vulnerabilities and expect to ship that coverage as soon as it is completed.
Blog

SEO Poisoning Marketplace Topping Search Results, Impersonating Top Financial Institutions

Introduction to the HaxorSEO MarketplaceFortra Intelligence and Research Experts (FIRE) have uncovered a group of active malicious threat actors operating since 2020. The group refers to themselves as Haxor, a slang word for hackers, and their marketplace as HxSEO, or HaxorSEO. HxSEO has established its primary base of operations and marketplace on Telegram and WhatsApp. HxSEO stands out for...
Blog

BEC Global Insights Report: December 2025

This report from Fortra Intelligence & Research Experts (FIRE) outlines key BEC trends for December 2025 based on active defense engagements. Findings include a 1% increase in overall attack volume compared to November, with gift cards as the leading cash-out method (52.8%) and Apple Store cards being most requested (50%).
Blog

January 2026 Patch Tuesday Analysis

Today’s Patch Tuesday Alert addresses Microsoft’s January 2026 Security Updates. The FIRE team is actively working on coverage for these vulnerabilities and expect to ship that coverage as soon as it is completed.
Blog

Top Five AI Threats to Watch Out For

AI threats can be plentiful and widespread. This blog breaks through the noise by identifying the top five riskiest AI threats to pay attention to this year. Fortra’s threat research breaks down what these threats are, how they are carried out by threat actors, and the risks they pose to all organizations regardless of size or industry.