Zero-Day Security Bug Likely Fueling Fortinet Firewall Attacks
ID: 12abaab8-c312-5634-8fd4-74c5ed6e4351
STIX ID: report--12abaab8-c312-5634-8fd4-74c5ed6e4351
Feed Name: Dark Reading
Date Published: 2025-01-14
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers at Arctic Wolf have identified an ongoing, opportunistic campaign targeting publicly exposed Fortinet FortiGate management interfaces (firmware versions ~7.0.14–7.0.16), likely exploiting an undisclosed zero-day to perform jsconsole logins, modify firewall configurations, create accounts, alter SSL VPN settings, and extract credentials (including via DCSync); organizations are advised to avoid exposing management interfaces, keep firmware patched, and enable syslog monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
