Fortinet Firewalls Hit With Malicious Configuration Changes
ID: c4ba0f8e-ddf7-5419-b3c7-8623b6efbf62
STIX ID: report--c4ba0f8e-ddf7-5419-b3c7-8623b6efbf62
Feed Name: Dark Reading
Threat Score
Arctic Wolf Labs observed a campaign beginning Jan. 15 where threat actors abused FortiCloud SSO to log into FortiGate devices, create accounts, grant VPN access, and quickly exfiltrate firewall configurations; the activity appears automated and may bypass previously released patches for CVE-2025-59718 and CVE-2025-59719, and Fortinet has acknowledged incomplete mitigation and is preparing a new fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
