Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls
ID: 8f955710-d481-5e97-8be3-e7a94f205885
STIX ID: report--8f955710-d481-5e97-8be3-e7a94f205885
Feed Name: Arctic Wolf
Date Published: 2025-01-10
Date Updated: 2026-07-25
Author: Stefan Hostetler, Julian Tuin, Trevor Daher, Jon Grimm, Alyssa Newbury, Joe Wedderspoon, and Markus Neis
Arctic Wolf Labs observed a widespread campaign exploiting Fortinet FortiGate web management/CLI (jsconsole) likely via a zero-day (later published as CVE-2024-55591) that enabled unauthorized admin logins, creation of super-admin and VPN accounts, establishment of SSL VPN tunnels, and subsequent lateral movement including DCSync; the report provides IoCs, timelines, affected firmware versions, detection guidance, and urgent remediation advice (remove/limit public management access, patch firmware).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
