FortiGate Firewall Exploitation Fuels Network Breaches in New Attack Wave
ID: e3312806-e5c9-5d5d-9991-a8bbb33a4f4d
STIX ID: report--e3312806-e5c9-5d5d-9991-a8bbb33a4f4d
Feed Name: GBHackers
Security teams observed active exploitation of FortiGate Single Sign-On and other FortiOS vulnerabilities allowing attackers to obtain administrative access, download and decrypt device configuration files to harvest AD service account credentials, create local administrative accounts on compromised appliances, join rogue workstations, perform password spraying and network enumeration, deploy RMM tools (Pulseway, MeshAgent) via cloud-hosted Java-sideloaded payloads, and steal NTDS.dit using Volume Shadow Copy; the report includes IoCs (domains, IPs, URLs, hostnames), recommended mitigations (patching, centralized log retention and monitoring), and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
