logo

Attackers exploit FortiGate devices to access sensitive network information

ID: d1137dea-018f-5429-9aea-0949846fc428

STIX ID: report--d1137dea-018f-5429-9aea-0949846fc428

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Attackers are exploiting FortiGate firewall vulnerabilities and weak administrative credentials to obtain admin access, extract configuration files containing service and LDAP credentials, decrypt those credentials to authenticate to Active Directory, deploy RMM tools and malware, and exfiltrate domain-controller data (NTDS.dit); impacted sectors include healthcare, government, and managed service providers, and recommended mitigations include patching, strong admin controls, and extended log retention/forwarding to a SIEM for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.