logo

Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls

ID: 8f955710-d481-5e97-8be3-e7a94f205885

STIX ID: report--8f955710-d481-5e97-8be3-e7a94f205885

Feed Name: Arctic Wolf

Threat Score
90/100

Date Published: 2025-01-10

Date Updated: 2026-07-25

Author: Stefan Hostetler, Julian Tuin, Trevor Daher, Jon Grimm, Alyssa Newbury, Joe Wedderspoon, and Markus Neis

...
...

Arctic Wolf Labs observed a widespread campaign exploiting Fortinet FortiGate web management/CLI (jsconsole) likely via a zero-day (later published as CVE-2024-55591) that enabled unauthorized admin logins, creation of super-admin and VPN accounts, establishment of SSL VPN tunnels, and subsequent lateral movement including DCSync; the report provides IoCs, timelines, affected firmware versions, detection guidance, and urgent remediation advice (remove/limit public management access, patch firmware).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.