Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Wave of Attacks Targeting FortiGate Firewalls

New Wave of Attacks Targeting FortiGate Firewalls

Posted on January 22, 2026January 22, 2026 By CWS

Menace actors are making configuration adjustments to FortiGate firewalls in a brand new wave of assaults harking back to a December 2025 marketing campaign, safety researchers warn.

Over the previous week, Arctic Wolf noticed automated assaults concentrating on FortiGate units to create new consumer accounts, modify configurations for VPN entry, and exfiltrate firewall information.

The exercise, the cybersecurity agency notes, is much like a month-old marketing campaign concentrating on CVE-2025-59718 and CVE-2025-59719 (CVSS rating of 9.8), two critical-severity authentication bypass vulnerabilities in Fortinet merchandise.

The bugs, the seller mentioned in early December, permit attackers to bypass the FortiCloud SSO login authentication by way of crafted SAML response messages.

Whereas the FortiCloud login function is disabled by default, it’s enabled when registering a brand new gadget to FortiCare from the gadget’s UI, except the administrator particularly disables it.

Roughly per week later, Arctic Wolf warned that risk actors began exploiting the safety defects towards FortiGate firewalls three days after Fortinet introduced patches for the 2 points.Commercial. Scroll to proceed studying.

Now, the cybersecurity firm says it has noticed a brand new wave of malicious SSO logins on FortiGate home equipment leading to malicious configuration adjustments.

The assaults originated from a small variety of internet hosting suppliers and sometimes focused the [email protected] account. Inside seconds after login, the attackers exported gadget configurations, probably by way of automation.

In line with Arctic Wolf, it’s unclear whether or not the exercise “is totally coated by the patch that originally addressed CVE-2025-59718 and CVE-2025-59719”.

Customers on Reddit recommend that the December patches for the 2 Fortinet vulnerabilities weren’t full, and that the seller is engaged on contemporary fixes for the bugs.

To stop the exploitation of the 2 vulnerabilities, customers are suggested to disable the FortiCloud login function by going to the settings menu and switching ‘Enable administrative login utilizing FortiCloud SSO’ off.

Associated: Fortinet Patches Important Vulnerabilities in FortiFone, FortiSIEM

Associated: Fortinet Warns of New Assaults Exploiting Outdated Vulnerability

Associated: Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week

Associated: Fortinet Confirms Lively Exploitation of Important FortiWeb Vulnerability

Security Week News Tags:Attacks, Firewalls, Fortigate, Targeting, Wave

Post navigation

Previous Post: Claroty Raises $150 Million in Series F Funding
Next Post: Malicious PyPI Package Mimic as Popular Sympy-Dev to Attack Millions of Users

Related Posts

Microsoft Dissects PipeMagic Modular Backdoor Microsoft Dissects PipeMagic Modular Backdoor Security Week News
Will AI-SPM Become the Standard Security Layer for Safe AI Adoption? Will AI-SPM Become the Standard Security Layer for Safe AI Adoption? Security Week News
PayPal Cybersecurity Breach Unveils Customer Data PayPal Cybersecurity Breach Unveils Customer Data Security Week News
AppSignal Raises  Million for Application Monitoring Solution AppSignal Raises $22 Million for Application Monitoring Solution Security Week News
OpenAI’s Sam Altman Warns of AI Voice Fraud Crisis in Banking OpenAI’s Sam Altman Warns of AI Voice Fraud Crisis in Banking Security Week News
OneDrive Gives Web Apps Full Read Access to All Files OneDrive Gives Web Apps Full Read Access to All Files Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark