Arctic Wolf detects surge in automated Fortinet FortiGate firewall configuration attacks
ID: 0c632a11-425d-547c-801f-c60b17ec7231
STIX ID: report--0c632a11-425d-547c-801f-c60b17ec7231
Feed Name: Security Affairs
Threat Score
Arctic Wolf observed a wave of automated malicious activity starting January 15, 2026, against Fortinet FortiGate devices that involved exploiting recent SSO authentication bypass vulnerabilities to perform malicious SSO logins, create persistent admin accounts, enable VPN access, and export firewall configurations (including hashed credentials); Arctic Wolf published detections and IoCs and is monitoring the evolving campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
