logo

Threat Spotlight: Credential Theft vs. Admin Control—Two Devastating Paths to VPN Exploitation

ID: 49f524e6-19af-521a-b715-95cb3add4452

STIX ID: report--49f524e6-19af-521a-b715-95cb3add4452

Feed Name: ReliaQuest Blog

Threat Score
88/100

Date Published: 2025-03-18

Date Updated: 2026-04-29

...
...

### Executive summary This report details widespread and ongoing exploitation of VPN vulnerabilities—primarily Fortinet CVE-2018-13379 and CVE-2022-40684—highlighting mass credential theft, administrative takeover via automated PoCs, large-scale incidents (including a 15,000-device FortiGate data leak and Ghost ransomware activity across 70+ countries), and defensive recommendations such as patching, segmentation, MFA, API monitoring, and continuous detection validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.