Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Leveraging Multiple AI Services to Compromise 600+ FortiGate Devices

Between Wed, Jan 11, 2026, and Thu, Feb 18, 2026, a financially-driven threat actor compromised over 600 FortiGate devices in more than 55 countries by exploiting commercial generative AI services.

Between Wed, Jan 11, 2026, and Thu, Feb 18, 2026, a financially-driven threat actor compromised over 600 FortiGate devices in more than 55 countries by exploiting commercial generative AI services.

The attack demonstrated that AI could significantly lower the technical barriers for conducting cyber operations. The threat actor utilized credential-based exploitation of FortiGate management interfaces exposed online, without deploying zero-day vulnerabilities or novel techniques.

Ports 443, 8443, 10443, and 4443 were systematically scanned to identify appliances with weak or reused credentials using single-factor authentication. Extracted FortiGate configuration files contained high-value data, such as SSL-VPN user credentials, administrative credentials, network topology data, IPsec VPN configurations, and firewall policies. These were processed using AI-assisted Python scripts to facilitate large-scale credential harvesting.

The targeting was opportunistic and automated mass scanning was used. Amazon Threat Intelligence noted patterns of compromise at the organizational level, particularly within managed service provider environments. Compromised devices were notably concentrated in South Asia, Latin America, the Caribbean, West Africa, Northern Europe, and Southeast Asia.

The threat actor used at least two commercial large language models (LLMs) during operations. One LLM was employed for tool development and attack planning, while the other assisted in network pivoting within compromised networks. A documented case revealed that the actor submitted a victim's network topology to an AI service for lateral movement guidance.

The post-exploitation phase involved deploying Meterpreter with the Mimikatz module to execute DCSync attacks against domain controllers, extracting NTLM credential databases from multiple Active Directory environments . Lateral movement was achieved through pass-the-hash, pass-the-ticket, and NTLM relay attacks. Veeam Backup & Replication servers were specifically targeted to disrupt recovery capabilities before ransomware deployment.

Despite the operation's scale, Amazon's analysis identified consistent skill limitations, with the actor abandoning targets with effective defenses. The AI-generated reconnaissance framework, written in Go and Python, exhibited unsophisticated development traits.

The attack demonstrated that AI could significantly lower the technical barriers for conducting cyber operations.
Michael Reeves · Thehackingpost

CVE ID Affected Product CVSS Score Description

CVE-2019-7192 FortiOS 9.8 Path traversal allowing unauthenticated credential access

CVE-2023-27532 Veeam Backup & Replication 7.5 Unauthenticated API access for credential extraction

CVE-2024-40711 Veeam Backup & Replication 9.8 Remote Code Execution via deserialization flaw

Amazon shared indicators of compromise with industry partners to coordinate disruption efforts. Organizations using FortiGate appliances are advised to:

Advertisement

Remove management interfaces from internet exposure. Enforce multi-factor authentication for all VPN and administrative access. Rotate SSL-VPN and administrative credentials. Audit Active Directory for DCSync activity (Event ID 4662).

Given the campaign's reliance on legitimate open-source tools, it is recommended to monitor for anomalous VPN authentication patterns, unexpected Active Directory replication, and unauthorized PowerShell module loading on backup servers.

IOC Value IOC Type First Seen Last Seen Annotation

212[.]11[.]64[.]250 IPv4 Jan 11, 2026 Feb 18, 2026 Threat actor infrastructure used for scanning and exploitation operations

185[.]196[.]11[.]225 IPv4 Jan 11, 2026 Feb 18, 2026 Threat actor infrastructure used for threat operations

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories