logo

SentinelOne Unmasks Exploitation of FortiGate Appliances as Gateways to Network Takeover

ID: 117c3f66-64c8-520b-8688-b66aea119102

STIX ID: report--117c3f66-64c8-520b-8688-b66aea119102

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-15

Date Updated: 2026-04-23

Author: Ddos

...
...

SentinelOne DFIR investigations reveal FortiGate NGFW appliances being actively compromised via high-severity authentication/SSO vulnerabilities and weak credentials; attackers extracted reversible configuration files to harvest service accounts, created local admin accounts, pivoted into Active Directory (including NTDS.dit extraction), and used RMM abuse and DLL side‑loading to maintain persistence—activities attributed to initial access brokers, ransomware groups, and state-aligned actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.