Fortinet FortiGate devices hit in automated attacks which create rogue accounts and steal firewall data



  • Hackers exploit Fortinet FortiGate SSO bug to steal firewall configuration data
  • FortiOS 7.4.10 patch incomplete; new versions planned to fully fix vulnerability
  • Stolen firewall data exposes network topology, VPNs, and security rules for further attacks

Cybercriminals seem to be taking advantage of a hole in a recent patch for Fortinet FortiGate instances, and are exploiting the vulnerability to create administrator accounts and steal firewall configuration data.

Security researchers at Arctic Wolf said they saw hackers abusing a bug in the single sign-on (SSO) feature to create accounts and export firewall configurations, most likely via an automated script.


https://cdn.mos.cms.futurecdn.net/oURxQ8dw8TJ2KxmqQDaio6-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img