logo

Fortinet FortiGate Devices Targeted by CyberStrikeAI, Allowing Hackers to Bypass Security

ID: 196d82f3-acf9-53d6-86b7-a06e2417ef0a

STIX ID: report--196d82f3-acf9-53d6-86b7-a06e2417ef0a

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Divya

...
...

Team Cymru uncovered CyberStrikeAI—an open-source, AI-native offensive security/orchestration tool—being used at scale to target Fortinet FortiGate devices, with over 600 appliances reportedly compromised across 55 countries; the campaign exploited exposed management ports and weak single-factor authentication rather than zero-day flaws. The developer (GitHub user Ed1s0nZ) is tied by researchers to Chinese state-affiliated projects, many malicious servers were hosted in China/Singapore/Hong Kong, and Team Cymru provides IoCs (e.g., 212.11.64.250, port 8080) and mitigation steps including disabling internet-exposed management interfaces and enforcing MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.