SentinelOne Unmasks Exploitation of FortiGate Appliances as Gateways to Network Takeover
ID: 117c3f66-64c8-520b-8688-b66aea119102
STIX ID: report--117c3f66-64c8-520b-8688-b66aea119102
Feed Name: securityonline.info
SentinelOne DFIR investigations reveal FortiGate NGFW appliances being actively compromised via high-severity authentication/SSO vulnerabilities and weak credentials; attackers extracted reversible configuration files to harvest service accounts, created local admin accounts, pivoted into Active Directory (including NTDS.dit extraction), and used RMM abuse and DLL side‑loading to maintain persistence—activities attributed to initial access brokers, ransomware groups, and state-aligned actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
