Investigating FortiManager Zero-Day Exploitation (CVE-2024-47575)
ID: ae1e392b-a13d-5b5f-a639-6a25dbc9a636
STIX ID: report--ae1e392b-a13d-5b5f-a639-6a25dbc9a636
Feed Name: Google Cloud Threat Intelligence
Mandiant and Fortinet investigated mass exploitation of FortiManager appliances via CVE-2024-47575 beginning as early as June 27, 2024, by a threat cluster tracked as UNC5820; the actor staged and exfiltrated FortiGate configuration data (including FortiOS hashed passwords) from 50+ devices, with observed inbound activity from 45.32.41.202 on TCP/541 and a staged archive at /tmp/.tm, and organizations with internet-exposed FortiManager instances are advised to perform immediate forensic investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
