FortiGate Firewalls Exploited in Wave of Attacks to Breach Networks and Steal Credentials
ID: a0152e6f-d4e2-5858-8968-cf7f033f79ac
STIX ID: report--a0152e6f-d4e2-5858-8968-cf7f033f79ac
Feed Name: cybersecurityNews.com
Threat Score
**SentinelOne investigated a series of early‑2026 intrusions where actors exploited multiple FortiGate vulnerabilities (including two high‑severity CVEs and a January zero‑day) to create local admin accounts, extract reversible FortiOS configuration files to harvest AD/LDAP credentials, and pivot into internal networks; two incidents detailed include an IAB-style foothold with rogue workstation joins and a rapid RMM deployment culminating in NTDS.dit exfiltration.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
