FortiGate firewalls hit by silent SSO intrusions and config theft
ID: 08dacf26-f711-5f48-8f52-15c3f1415d1a
STIX ID: report--08dacf26-f711-5f48-8f52-15c3f1415d1a
Feed Name: The Register (Security)
Threat Score
Arctic Wolf has observed automated attacks starting mid-January that exploit SSO authentication bypasses in FortiGate appliances (linked to CVE-2025-59718 and CVE-2025-59719) to create admin accounts, modify firewall and VPN settings, and exfiltrate full device configurations; affected admins report evidence of continued bypass on systems believed to be patched, and shared logs identify activity from IP 104.28.244.114 and the SSO address [email protected].
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
