logo

Mandiant says new Fortinet flaw has been exploited since June

ID: 1598ce65-d671-5390-a0f3-0cbdb8fa980e

STIX ID: report--1598ce65-d671-5390-a0f3-0cbdb8fa980e

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-10-24

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A FortiManager authentication zero-day (CVE-2024-47575, “FortiJump”) has been actively exploited since June 2024 to register attacker-controlled FortiManager/FortiGate devices, execute API commands, and exfiltrate managed FortiGate configuration data (including hashed passwords); Mandiant attributes the intrusions to UNC5820, Fortinet released patches and mitigations, and the report includes IOCs and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.