logo

FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise

ID: 493e25ea-149e-5bec-a9e4-48543dd21768

STIX ID: report--493e25ea-149e-5bec-a9e4-48543dd21768

Feed Name: SentinelOne Blog

Threat Score
90/100

Date Published: 2026-03-10

Date Updated: 2026-04-30

Author: Alex Delamotte, Stephen Bromfield, Mary Braden Murphy & Amey Patne

...
...

SentinelOne DFIR documents multiple incidents (late 2025–early 2026) in which attackers exploited FortiGate appliances—via CVE-2025-59718, CVE-2025-59719, CVE-2026-24858 and credential-based logins—to download configuration files, recover service account credentials, create backdoor administrative accounts, join rogue workstations to Active Directory, deploy abused RMM tools (Pulseway, MeshAgent), and exfiltrate NTDS.dit; the report provides IOCs (IPs, domains, URLs, account and host names), SIEM/logging recommendations, and detailed forensic guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.