logo

Fortinet Firewalls Hit With Malicious Configuration Changes

ID: c4ba0f8e-ddf7-5419-b3c7-8623b6efbf62

STIX ID: report--c4ba0f8e-ddf7-5419-b3c7-8623b6efbf62

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-01-22

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Arctic Wolf Labs observed a campaign beginning Jan. 15 where threat actors abused FortiCloud SSO to log into FortiGate devices, create accounts, grant VPN access, and quickly exfiltrate firewall configurations; the activity appears automated and may bypass previously released patches for CVE-2025-59718 and CVE-2025-59719, and Fortinet has acknowledged incomplete mitigation and is preparing a new fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.