logo

Russian Cyber Threat Actor Uses GenAI to Compromise Fortinet Firewalls

ID: 424409ce-d16a-52b3-bdc0-1cb7dac97d7c

STIX ID: report--424409ce-d16a-52b3-bdc0-1cb7dac97d7c

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-02-23

Date Updated: 2026-04-22

...
...

AWS Threat Intelligence reported a low-skilled, financially motivated actor leveraged commercial generative AI to scale a campaign (11 Jan–18 Feb 2026) that compromised over 600 FortiGate management interfaces across 55+ countries by scanning exposed interfaces and reusing credentials. After gaining VPN access the actor used AI-assisted reconnaissance and common offensive tools (Meterpreter/Mimikatz, Nuclei, gogo scanner) to extract credentials, perform lateral movement and target backup infrastructure; AWS noted no FortiGate vulnerability exploitation and recommended patching, credential hygiene, segmentation and post-exploitation detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.