AWS says more than 600 FortiGate firewalls hit in AI-augmented campaign
ID: 85d2c667-45c9-59bc-a750-eab02371a622
STIX ID: report--85d2c667-45c9-59bc-a750-eab02371a622
Feed Name: The Register (Security)
Cybercriminals leveraged commercial generative AI to automate large-scale scanning and credential-guessing against internet-exposed FortiGate management interfaces, compromising more than 600 devices across 55 countries in roughly one month; attackers exfiltrated configuration files (including admin and VPN credentials), pursued lateral movement into Active Directory and backup systems, and favored high-volume opportunistic targeting. AWS attributes the activity to a financially motivated Russian-speaking group and emphasizes that basic hygiene—removing management interfaces from the public internet, enforcing MFA, and preventing password reuse—would have prevented many of the compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
