logo

FortiGate firewalls hit by silent SSO intrusions and config theft

ID: 08dacf26-f711-5f48-8f52-15c3f1415d1a

STIX ID: report--08dacf26-f711-5f48-8f52-15c3f1415d1a

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-01-22

Date Updated: 2026-04-26

Author: Carly Page

...
...

Arctic Wolf has observed automated attacks starting mid-January that exploit SSO authentication bypasses in FortiGate appliances (linked to CVE-2025-59718 and CVE-2025-59719) to create admin accounts, modify firewall and VPN settings, and exfiltrate full device configurations; affected admins report evidence of continued bypass on systems believed to be patched, and shared logs identify activity from IP 104.28.244.114 and the SSO address [email protected].

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.