Fortinet

The UK's "Medicines Discovery Catapult"; Hitachi; Bletchley Park, among the names in a trove of firewall passwords and rules leaked this week.

A "missing authentication for critical function vulnerability"? Well, this is novel!

But details of campaign blasted by one industry veteran for giving away too much detail on web shells on victims' systems

"It is important that organizations practice the ‘assume breach’ principle..." YARA rules, hashes etc. available for defenders.

"It is a pre-auth RCE [and] has been proven to be exploitable in a consistent manner; we found it during a Red Team engagement and have exploited it remotely..."