Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

FortiGate Firewalls Exploited in Wave of Attacks to Breach Networks and Steal Credentials

A series of security breaches occurred in early 2026, where threat actors targeted FortiGate Next-Generation Firewalls (NGFW) to gain persistent access to enterprise networks. These incidents were intercepted during the lateral movement phase, preventing…

A series of security breaches occurred in early 2026, where threat actors targeted FortiGate Next-Generation Firewalls (NGFW) to gain persistent access to enterprise networks. These incidents were intercepted during the lateral movement phase, preventing full execution of attacker objectives.

The attack wave, discovered by SentinelOne, exploited three critical Fortinet vulnerabilities disclosed between December 2025 and February 2026.

CVE-2025-59718 and CVE-2025-59719 (CVSS: 9.8) both involve improper verification of cryptographic signatures (CWE-347), allowing unauthenticated attackers to send crafted SAML tokens and gain administrative access to FortiGate devices without valid credentials. CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog with a remediation deadline of January 23, 2026.

A third vulnerability, CVE-2026-24858 , was actively exploited as a zero-day in January 2026, enabling attackers to access victim FortiGate devices using their own FortiCloud account. This was identified as a new vulnerability, not a patch bypass.

Fortinet temporarily disabled FortiCloud SSO on January 26, 2026, and released firmware patches requiring customer upgrades before restoring SSO functionality.

In addition to these exploits, researchers observed that less skilled actors are scanning for open FortiGate instances and attempting logins with weak or default credentials, facilitating initial access.

Configuration Files Stripped for Credentials

Once inside, attackers used the show full-configuration command to extract the complete FortiGate configuration file. FortiOS employs a reversible encryption scheme, allowing adversaries to decrypt embedded service account credentials, particularly LDAP and Active Directory (AD) accounts, and move into the internal network.

These incidents were intercepted during the lateral movement phase, preventing full execution of attacker objectives.
Carter Hartwell · Thehackingpost

Incident 1: IAB Foothold and Rogue Domain Workstations

The first incident likely began in late November 2025 and remained undetected until February 2026, resulting in a dwell time of approximately two months.

After access was gained, the threat actor created a local FortiGate admin account named "support" and implemented four permissive firewall policies, enabling unrestricted traffic across all network zones.

The low activity volume indicates an Initial Access Broker (IAB) establishing and validating access before selling it to another party.

In February 2026, the attacker authenticated to Active Directory using the decrypted fortidcagent service account credentials from IP address 193.24.211[.]61 and exploited the mS-DS-MachineAccountQuota attribute to join two rogue workstations — WIN-X8WRBOSK0OF and WIN-YRSXLEONJY2 to the corporate domain.

Password spraying attempts originating from the FortiGate appliance IP, alongside artifacts linked to SoftPerfect Network Scanner, triggered security alerts, thereby halting further lateral movement.

Incident 2: RMM Deployment and NTDS Exfiltration

In the second incident, investigated in late January 2026, the attacker created a local admin account named "ssl-admin" on the compromised FortiGate device. Within 10 minutes, the attacker accessed multiple internal servers using domain administrator credentials obtained from the decrypted configuration file.

Advertisement

Files were staged in C:\ProgramData\USOShared , and two Remote Monitoring and Management (RMM) tools — Pulseway and MeshAgent — were deployed from attacker-controlled Google Cloud Storage and AWS S3 buckets, respectively.

MeshAgent was concealed by setting the Windows Registry value SystemComponent=1 to hide it from the Programs and Features list. The attacker used DLL side-loading via malicious Java-named DLLs to communicate with attacker-controlled domains ndibstersoft[.]com and neremedysoft[.]com .

To complete the attack chain, the threat actor created a Volume Shadow Copy of the primary domain controller, extracted the NTDS.dit file and SYSTEM registry hive using makecab , and exfiltrated the compressed archives to a Cloudflare-owned IP (172.67.196[.]232) before deleting the local copies.

SentinelOne emphasized that inadequate log retention significantly impeded both investigations, preventing accurate identification of the initial access vector. Organizations are advised to implement a minimum of 14 days of FortiGate log retention, with 60 to 90 days recommended. Key defensive actions include:

Immediately apply all available Fortinet firmware patches for CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858. Rotate all LDAP and AD credentials associated with FortiGate appliances following any suspected compromise. Enforce strong administrative access controls and eliminate default or weak credentials on network edge devices. Monitor for unauthorized local admin account creation on FortiGate appliances (e.g., names like "support," "ssl-admin," "helpdesk"). Audit mS-DS-MachineAccountQuota settings to restrict unauthorized workstation joins to the domain. Ensure EDR telemetry from servers adjacent to the NGFW is actively monitored, as the appliances themselves cannot host endpoint detection tools.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories