China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally
ID: 290af563-3107-5c95-9792-be3aed641a47
STIX ID: report--290af563-3107-5c95-9792-be3aed641a47
Feed Name: The Hacker News
State-backed Chinese threat actors exploited a critical Fortinet FortiGate remote code execution vulnerability (CVE-2022-42475, CVSS 9.8) between 2022–2023 to compromise about 20,000 devices worldwide—infecting an estimated 14,000 during a zero-day period—and deployed a persistent backdoor named COATHANGER to maintain access, targeting Western governments, international organizations, and numerous defense-sector companies; the incident highlights the elevated risk from internet-facing edge appliances that often lack EDR protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
