Chinese hackers exploit Fortinet VPN zero-day to steal credentials
ID: 7c6b4aad-26f3-5d75-addb-942033b7af2a
STIX ID: report--7c6b4aad-26f3-5d75-addb-942033b7af2a
Feed Name: Bleeping Computer
Threat Score
Volexity reports that Chinese APT 'BrazenBamboo' is weaponizing a FortiClient Windows VPN zero-day via its DeepData toolkit to extract VPN usernames, passwords, and gateway details from JSON objects left in process memory; the flaw was reported in July 2024, remains unpatched, and enables credential theft, initial access, and lateral movement — IoCs and mitigation recommendations are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
