FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
ID: 493e25ea-149e-5bec-a9e4-48543dd21768
STIX ID: report--493e25ea-149e-5bec-a9e4-48543dd21768
Feed Name: SentinelOne Blog
Date Published: 2026-03-10
Date Updated: 2026-04-30
Author: Alex Delamotte, Stephen Bromfield, Mary Braden Murphy & Amey Patne
SentinelOne DFIR documents multiple incidents (late 2025–early 2026) in which attackers exploited FortiGate appliances—via CVE-2025-59718, CVE-2025-59719, CVE-2026-24858 and credential-based logins—to download configuration files, recover service account credentials, create backdoor administrative accounts, join rogue workstations to Active Directory, deploy abused RMM tools (Pulseway, MeshAgent), and exfiltrate NTDS.dit; the report provides IOCs (IPs, domains, URLs, account and host names), SIEM/logging recommendations, and detailed forensic guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
