Hackers breach Fortinet FortiGate devices, steal firewall configs
ID: e8a60c08-e2e2-5011-84db-4601c7d1348f
STIX ID: report--e8a60c08-e2e2-5011-84db-4601c7d1348f
Feed Name: Bleeping Computer
Fortinet FortiGate devices are being actively targeted by automated attacks that exploit a FortiCloud SSO authentication bypass (CVE-2025-59718 and related CVE-2025-59719) to create administrative/VPN accounts and rapidly export firewall configurations. Reports indicate some patched versions may be bypassed, Arctic Wolf and customer logs provide IoCs (e.g., [email protected], 104.28.244.114), Shadowserver reports ~11,000 devices with FortiCloud SSO exposed, and CISA has listed the vulnerability as exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
