logo

2022 zero day was used to raid Fortigate firewall configs. Somebody just released them.

ID: 14f1dc6c-5899-575b-89bf-5d23f041c7af

STIX ID: report--14f1dc6c-5899-575b-89bf-5d23f041c7af

Feed Name: DoublePulsar

Threat Score
90/100

Date Published: 2025-01-16

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

A public release of FortiOS configuration dumps (assembled October 2022) affecting 15,474 devices has exposed plaintext usernames and passwords, device management certificates, and full firewall rules; the collector attributes initial exploitation to CVE-2022-40684. Organizations should verify whether they were patched at the time, identify impacted IPs, rotate device credentials, and assess risks from publicly disclosed firewall policies and certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.