Russian Cyber Threat Actor Uses GenAI to Compromise Fortinet Firewalls
ID: 424409ce-d16a-52b3-bdc0-1cb7dac97d7c
STIX ID: report--424409ce-d16a-52b3-bdc0-1cb7dac97d7c
Feed Name: Infosecurity Magazine (News)
AWS Threat Intelligence reported a low-skilled, financially motivated actor leveraged commercial generative AI to scale a campaign (11 Jan–18 Feb 2026) that compromised over 600 FortiGate management interfaces across 55+ countries by scanning exposed interfaces and reusing credentials. After gaining VPN access the actor used AI-assisted reconnaissance and common offensive tools (Meterpreter/Mimikatz, Nuclei, gogo scanner) to extract credentials, perform lateral movement and target backup infrastructure; AWS noted no FortiGate vulnerability exploitation and recommended patching, credential hygiene, segmentation and post-exploitation detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
