Arctic Wolf Observes Malicious SSO Logins on FortiGate Devices Following Disclosure of CVE-2025-59718 and CVE-2025-59719
ID: 72469957-46a4-5f2d-8296-1d3672124f9b
STIX ID: report--72469957-46a4-5f2d-8296-1d3672124f9b
Feed Name: Arctic Wolf
Arctic Wolf observed active exploitation of Fortinet authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719) enabling unauthenticated FortiCloud SSO admin logins and subsequent configuration exfiltration from FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager devices; the bulletin includes attacker IP IOCs, example logs, recommended mitigations (reset credentials, restrict management access, disable FortiCloud SSO, and upgrade to fixed versions), and notes that detections are in place.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
