logo

Zero-Day Security Bug Likely Fueling Fortinet Firewall Attacks

ID: 12abaab8-c312-5634-8fd4-74c5ed6e4351

STIX ID: report--12abaab8-c312-5634-8fd4-74c5ed6e4351

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-01-14

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers at Arctic Wolf have identified an ongoing, opportunistic campaign targeting publicly exposed Fortinet FortiGate management interfaces (firmware versions ~7.0.14–7.0.16), likely exploiting an undisclosed zero-day to perform jsconsole logins, modify firewall configurations, create accounts, alter SSL VPN settings, and extract credentials (including via DCSync); organizations are advised to avoid exposing management interfaces, keep firmware patched, and enable syslog monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.