China's FortiGate attacks more extensive than first thought
ID: ebbedb97-5e17-5f1b-9002-defc1b5c12b6
STIX ID: report--ebbedb97-5e17-5f1b-9002-defc1b5c12b6
Feed Name: The Register (Security)
Threat Score
The Netherlands' NCSC warns a China-linked mass-exploitation campaign used a critical FortiOS SSL‑VPN zero-day (CVE-2022-42475) to compromise roughly 20,000 FortiGate devices (about 14,000 during a zero-day window) and deploy the Coathanger RAT for persistent access; victims include Western governments, international organizations and numerous defence firms, and infections often require device reformatting to remove, highlighting rising risk from vulnerable edge devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
