600+ FortiGate Devices Hacked by AI-Armed Amateur
ID: 577a192b-57a6-5375-b17e-4e085caa480f
STIX ID: report--577a192b-57a6-5375-b17e-4e085caa480f
Feed Name: Dark Reading
A financially motivated actor used generative AI to automate scanning and credential abuse against exposed FortiGate management ports, compromising more than 600 devices across 55+ countries. The campaign focused on extracting device configurations and credentials, then targeted Veeam backup servers and Active Directory to obtain elevated access and backup credentials; AWS published IoCs and recommended mitigations such as removing management interfaces from the Internet, enforcing MFA, rotating credentials, and auditing unusual backup or DCSync activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
