logo

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used

ID: 45dd4988-9778-5c45-8b74-752d2d54be0f

STIX ID: report--45dd4988-9778-5c45-8b74-752d2d54be0f

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-01-14

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Arctic Wolf Labs observed a mass exploitation campaign against internet-exposed Fortinet FortiGate firewalls (affecting multiple firmware versions) that abused an authentication-bypass zero-day ultimately assigned CVE-2024-55591. Attackers performed automated jsconsole logins (often from spoofed IPs), changed web-CLI settings, created super-admin and SSL VPN accounts, established SSL VPN tunnels, and harvested Active Directory credentials (DCSync) for lateral movement; Fortinet released a critical-severity advisory and fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.