Fortinet FortiGate devices hit in automated attacks that create rogue accounts and steal firewall data


  • Hackers are exploiting Fortinet FortiGate SSO flaws to steal firewall configuration data
  • FortiOS 7.4.10 patch incomplete; new versions planned to fully fix vulnerability
  • Stolen firewall data exposes network topology, VPNs and security rules for further attacks

Cybercriminals appear to be exploiting a hole in a recent patch for Fortinet FortiGate instances and are exploiting the vulnerability to create administrator accounts and steal firewall configuration data.

Security researchers at Arctic Wolf said they saw hackers exploit a flaw in the single sign-on (SSO) feature to create accounts and export firewall configurations, likely via an automated script.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top