logo

Hackers breach Fortinet FortiGate devices, steal firewall configs

ID: e8a60c08-e2e2-5011-84db-4601c7d1348f

STIX ID: report--e8a60c08-e2e2-5011-84db-4601c7d1348f

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-01-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Fortinet FortiGate devices are being actively targeted by automated attacks that exploit a FortiCloud SSO authentication bypass (CVE-2025-59718 and related CVE-2025-59719) to create administrative/VPN accounts and rapidly export firewall configurations. Reports indicate some patched versions may be bypassed, Arctic Wolf and customer logs provide IoCs (e.g., [email protected], 104.28.244.114), Shadowserver reports ~11,000 devices with FortiCloud SSO exposed, and CISA has listed the vulnerability as exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.