FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials
Threat actors are leveraging FortiGate Next-Generation Firewall (NGFW) appliances as entry points to compromise target networks in a new campaign that cybersecurity researchers are drawing attention to.
According to a research released today by SentinelOne, the activity entails taking advantage of previously revealed security flaws or weak credentials in order to extract configuration files that contain information on network topology and service account credentials. According to the security group, the campaign has targeted settings related to government, healthcare, and managed service providers.
According to security researchers Alex Delamotte, Stephen Bromfield, Mary Braden Murphy, and Amey Patne, FortiGate network appliances have significant access to the environments they were...


