comdak's User Avatar

@comdak

in /hacking 3 days ago

FortiGate firewalls hit by silent SSO attacks & config theft... still happening after latest patch

FortiGate firewalls hit by silent SSO attacks & config theft • The Register - Featured Image

FortiGate firewalls hit by silent SSO attacks & config theft • The Register

www.theregister.com - favicontheregister.com
TLDR

FortiGate firewalls are experiencing silent attacks where attackers bypass SSO protections to reconfigure settings, create backdoor admin users, and steal configuration files. Arctic Wolf warns of automated malicious activity targeting FortiGate appliances since January 15. Despite patches for critical authentication bypass bugs, admins report ongoing intrusions, suggesting a patch bypass for CVE-2025-59718. Fortinet is preparing new releases to fully address the issue.

4Score: 4

0 Comments