Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Wave of Attacks Targeting FortiGate Firewalls

New Wave of Attacks Targeting FortiGate Firewalls

Posted on January 22, 2026January 22, 2026 By CWS

Menace actors are making configuration adjustments to FortiGate firewalls in a brand new wave of assaults harking back to a December 2025 marketing campaign, safety researchers warn.

Over the previous week, Arctic Wolf noticed automated assaults concentrating on FortiGate units to create new consumer accounts, modify configurations for VPN entry, and exfiltrate firewall information.

The exercise, the cybersecurity agency notes, is much like a month-old marketing campaign concentrating on CVE-2025-59718 and CVE-2025-59719 (CVSS rating of 9.8), two critical-severity authentication bypass vulnerabilities in Fortinet merchandise.

The bugs, the seller mentioned in early December, permit attackers to bypass the FortiCloud SSO login authentication by way of crafted SAML response messages.

Whereas the FortiCloud login function is disabled by default, it’s enabled when registering a brand new gadget to FortiCare from the gadget’s UI, except the administrator particularly disables it.

Roughly per week later, Arctic Wolf warned that risk actors began exploiting the safety defects towards FortiGate firewalls three days after Fortinet introduced patches for the 2 points.Commercial. Scroll to proceed studying.

Now, the cybersecurity firm says it has noticed a brand new wave of malicious SSO logins on FortiGate home equipment leading to malicious configuration adjustments.

The assaults originated from a small variety of internet hosting suppliers and sometimes focused the [email protected] account. Inside seconds after login, the attackers exported gadget configurations, probably by way of automation.

In line with Arctic Wolf, it’s unclear whether or not the exercise “is totally coated by the patch that originally addressed CVE-2025-59718 and CVE-2025-59719”.

Customers on Reddit recommend that the December patches for the 2 Fortinet vulnerabilities weren’t full, and that the seller is engaged on contemporary fixes for the bugs.

To stop the exploitation of the 2 vulnerabilities, customers are suggested to disable the FortiCloud login function by going to the settings menu and switching ‘Enable administrative login utilizing FortiCloud SSO’ off.

Associated: Fortinet Patches Important Vulnerabilities in FortiFone, FortiSIEM

Associated: Fortinet Warns of New Assaults Exploiting Outdated Vulnerability

Associated: Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week

Associated: Fortinet Confirms Lively Exploitation of Important FortiWeb Vulnerability

Security Week News Tags:Attacks, Firewalls, Fortigate, Targeting, Wave

Post navigation

Previous Post: Claroty Raises $150 Million in Series F Funding
Next Post: Malicious PyPI Package Mimic as Popular Sympy-Dev to Attack Millions of Users

Related Posts

ClickFix Attacks Against macOS Users Evolving ClickFix Attacks Against macOS Users Evolving Security Week News
Zafran Security Raises  Million in Series C Funding Zafran Security Raises $60 Million in Series C Funding Security Week News
Critical Vulnerability in n8n Poses Server Risks Critical Vulnerability in n8n Poses Server Risks Security Week News
640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack 640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack Security Week News
In Other News: Hackers Not Behind Blackout, CISO Docuseries, Dior Data Breach In Other News: Hackers Not Behind Blackout, CISO Docuseries, Dior Data Breach Security Week News
Upwind Raises 0 Million at .5 Billion Valuation Upwind Raises $250 Million at $1.5 Billion Valuation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News