15K Fortigate Firewall Configs Leaked By Belsen Group: Dumped Using Zero-Day in 2022
ID: d1f0b310-1b71-573f-a587-84cb004529a8
STIX ID: report--d1f0b310-1b71-573f-a587-84cb004529a8
Feed Name: CloudSEK Blog
Threat Score
This report describes a large-scale leak of over 15,000 FortiGate firewall configurations allegedly published by the Belsen Group; the leak is linked to mass exploitation of an authentication-bypass zero-day (CVE-2022-40684) in 2022 and includes exposed credentials, firewall rules, and device certificates, with an associated pastebin of affected IPs and recommended mitigations (credential changes, certificate rotation, firewall audits, and forensic investigation).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
