logo

FortiGate Firewalls Exploited in Wave of Attacks to Breach Networks and Steal Credentials

ID: a0152e6f-d4e2-5858-8968-cf7f033f79ac

STIX ID: report--a0152e6f-d4e2-5858-8968-cf7f033f79ac

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-03-15

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**SentinelOne investigated a series of early‑2026 intrusions where actors exploited multiple FortiGate vulnerabilities (including two high‑severity CVEs and a January zero‑day) to create local admin accounts, extract reversible FortiOS configuration files to harvest AD/LDAP credentials, and pivot into internal networks; two incidents detailed include an IAB-style foothold with rogue workstation joins and a rapid RMM deployment culminating in NTDS.dit exfiltration.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.