logo

Fortinet: FortiGate config leaks are genuine but misleading

ID: 39b06f04-7b59-54aa-a6fe-f45ec804bf0b

STIX ID: report--39b06f04-7b59-54aa-a6fe-f45ec804bf0b

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2025-01-17

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Fortinet confirmed that configuration files from FortiGate devices—containing IP addresses, firewall rules and some plaintext passwords—were stolen during a 2022 zero-day compromise and recently published by the Belsen Group, affecting around 15,000 devices; Fortinet urges patching, credential refreshes, and customer outreach. The report also highlights a separate suspected mass zero-day exploitation campaign against FortiGate firewalls in late 2024, increasing the urgency for mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.