Fortinet FortiGate devices suffer automated attacks that create fraudulent accounts and steal data from the firewall



  • Hackers Leverage Fortinet FortiGate SSO Bug to Steal Firewall Configuration Data
  • FortiOS 7.4.10 patch incomplete; new releases planned to fully fix the vulnerability
  • Stolen firewall data exposes network topology, VPNs, and security rules to future attacks

Cybercriminals appear to be exploiting a hole in a recent patch for Fortinet FortiGate instances and are exploiting the vulnerability to create administrator accounts and steal firewall configuration data.

Security researchers at Arctic Wolf said they saw hackers abusing a bug in the single sign-on (SSO) feature to create accounts and export firewall settings, most likely through an automated script.



Leave a Comment

Your email address will not be published. Required fields are marked *