Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used
ID: 45dd4988-9778-5c45-8b74-752d2d54be0f
STIX ID: report--45dd4988-9778-5c45-8b74-752d2d54be0f
Feed Name: The Register (Security)
Arctic Wolf Labs observed a mass exploitation campaign against internet-exposed Fortinet FortiGate firewalls (affecting multiple firmware versions) that abused an authentication-bypass zero-day ultimately assigned CVE-2024-55591. Attackers performed automated jsconsole logins (often from spoofed IPs), changed web-CLI settings, created super-admin and SSL VPN accounts, established SSL VPN tunnels, and harvested Active Directory credentials (DCSync) for lateral movement; Fortinet released a critical-severity advisory and fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
