Attackers exploit FortiGate devices to access sensitive network information
ID: d1137dea-018f-5429-9aea-0949846fc428
STIX ID: report--d1137dea-018f-5429-9aea-0949846fc428
Feed Name: Security Affairs
Attackers are exploiting FortiGate firewall vulnerabilities and weak administrative credentials to obtain admin access, extract configuration files containing service and LDAP credentials, decrypt those credentials to authenticate to Active Directory, deploy RMM tools and malware, and exfiltrate domain-controller data (NTDS.dit); impacted sectors include healthcare, government, and managed service providers, and recommended mitigations include patching, strong admin controls, and extended log retention/forwarding to a SIEM for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
