logo

Chinese hackers exploit Fortinet VPN zero-day to steal credentials

ID: 7c6b4aad-26f3-5d75-addb-942033b7af2a

STIX ID: report--7c6b4aad-26f3-5d75-addb-942033b7af2a

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-11-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Volexity reports that Chinese APT 'BrazenBamboo' is weaponizing a FortiClient Windows VPN zero-day via its DeepData toolkit to extract VPN usernames, passwords, and gateway details from JSON objects left in process memory; the flaw was reported in July 2024, remains unpatched, and enables credential theft, initial access, and lateral movement — IoCs and mitigation recommendations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.