UNC5820 exploiting FortiManager flaw (Campaign)
ID: 3a8c2cd1-bf89-5593-ae2f-9306ede62fd0
STIX ID: report--3a8c2cd1-bf89-5593-ae2f-9306ede62fd0
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-10-24
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers identified active exploitation of a FortiManager zero-day (CVE-2024-47575) by UNC5820 beginning June 2024; the flaw in the fgfmd daemon enabled remote arbitrary command execution and was used to exfiltrate FortiGate configuration data (including credentials and policies). Compromised devices produced compressed files containing IP addresses and serial numbers and established outbound connections following file creation, with Fortinet issuing mitigations and updates to address the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
