Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Wave of Attacks Targeting FortiGate Firewalls

New Wave of Attacks Targeting FortiGate Firewalls

Posted on January 22, 2026January 22, 2026 By CWS

Menace actors are making configuration adjustments to FortiGate firewalls in a brand new wave of assaults harking back to a December 2025 marketing campaign, safety researchers warn.

Over the previous week, Arctic Wolf noticed automated assaults concentrating on FortiGate units to create new consumer accounts, modify configurations for VPN entry, and exfiltrate firewall information.

The exercise, the cybersecurity agency notes, is much like a month-old marketing campaign concentrating on CVE-2025-59718 and CVE-2025-59719 (CVSS rating of 9.8), two critical-severity authentication bypass vulnerabilities in Fortinet merchandise.

The bugs, the seller mentioned in early December, permit attackers to bypass the FortiCloud SSO login authentication by way of crafted SAML response messages.

Whereas the FortiCloud login function is disabled by default, it’s enabled when registering a brand new gadget to FortiCare from the gadget’s UI, except the administrator particularly disables it.

Roughly per week later, Arctic Wolf warned that risk actors began exploiting the safety defects towards FortiGate firewalls three days after Fortinet introduced patches for the 2 points.Commercial. Scroll to proceed studying.

Now, the cybersecurity firm says it has noticed a brand new wave of malicious SSO logins on FortiGate home equipment leading to malicious configuration adjustments.

The assaults originated from a small variety of internet hosting suppliers and sometimes focused the [email protected] account. Inside seconds after login, the attackers exported gadget configurations, probably by way of automation.

In line with Arctic Wolf, it’s unclear whether or not the exercise “is totally coated by the patch that originally addressed CVE-2025-59718 and CVE-2025-59719”.

Customers on Reddit recommend that the December patches for the 2 Fortinet vulnerabilities weren’t full, and that the seller is engaged on contemporary fixes for the bugs.

To stop the exploitation of the 2 vulnerabilities, customers are suggested to disable the FortiCloud login function by going to the settings menu and switching ‘Enable administrative login utilizing FortiCloud SSO’ off.

Associated: Fortinet Patches Important Vulnerabilities in FortiFone, FortiSIEM

Associated: Fortinet Warns of New Assaults Exploiting Outdated Vulnerability

Associated: Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week

Associated: Fortinet Confirms Lively Exploitation of Important FortiWeb Vulnerability

Security Week News Tags:Attacks, Firewalls, Fortigate, Targeting, Wave

Post navigation

Previous Post: Claroty Raises $150 Million in Series F Funding
Next Post: Malicious PyPI Package Mimic as Popular Sympy-Dev to Attack Millions of Users

Related Posts

North Korean Hackers Targeted Hundreds in Fake Job Interview Attacks North Korean Hackers Targeted Hundreds in Fake Job Interview Attacks Security Week News
Novee Emerges From Stealth With .5 Million in Funding Novee Emerges From Stealth With $51.5 Million in Funding Security Week News
Malicious NPM Packages Target Cursor AI’s macOS Users Malicious NPM Packages Target Cursor AI’s macOS Users Security Week News
Atlassian Patches Critical Apache Tika Flaw Atlassian Patches Critical Apache Tika Flaw Security Week News
UK Government Acknowledges It Is Investigating Cyber Incident After Media Reports UK Government Acknowledges It Is Investigating Cyber Incident After Media Reports Security Week News
RSAC Unveils Quantickle: Open Source Threat Visualization Tool RSAC Unveils Quantickle: Open Source Threat Visualization Tool Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Threats and Global Cyber Developments
  • Telnyx SDK on PyPI Compromised by Hackers
  • European Commission Confirms Cyberattack on Cloud Systems
  • CanisterWorm Malware Threatens Cloud Security Globally
  • Huskeys Secures $8 Million in Seed Funding for ESM Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Threats and Global Cyber Developments
  • Telnyx SDK on PyPI Compromised by Hackers
  • European Commission Confirms Cyberattack on Cloud Systems
  • CanisterWorm Malware Threatens Cloud Security Globally
  • Huskeys Secures $8 Million in Seed Funding for ESM Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark