logo

New Campaign Targets FortiGate Firewalls with Unauthorized Config Changes

ID: 745049c4-e8fa-5a0b-9ad4-2816c62e8a19

STIX ID: report--745049c4-e8fa-5a0b-9ad4-2816c62e8a19

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

Arctic Wolf has observed an active, automated campaign (since Jan 15, 2026) targeting FortiGate firewalls through unauthorized SSO logins that rapidly download firewall configuration files and create secondary administrative accounts for persistence. The activity mirrors exploitation of authentication-bypass CVEs disclosed in late 2025, uses generic admin-like account names (e.g., [email protected], [email protected], secadmin), and aims to steal hashed credentials and network configurations; recommended mitigations include disabling FortiCloud SSO, resetting credentials, and restricting management interface access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.