Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

Madonna features surprise star in Sabrina Carpenter’s ‘Bring Your Love’ video

Discover the Digital Twin That Revolutionizes Online Sales: The Story of Farmasi and a Collaborator Who Changes Everything

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » FortiGate devices are exploited to infiltrate the network and steal service account credentials
Celebrities

FortiGate devices are exploited to infiltrate the network and steal service account credentials

By March 10, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 10, 2026Network security/vulnerabilities

Cybersecurity researchers are warning of a new campaign in which attackers are exploiting FortiGate next-generation firewall (NGFW) appliances as entry points to penetrate victim networks.

This activity involves exploiting recently disclosed security vulnerabilities or weak credentials to extract configuration files containing service account credentials and network topology information, SentinelOne said in a report released today. Security groups say the campaign has identified environments related to healthcare, government, and managed service providers.

“FortiGate network appliances have significant access to the environments they are installed to protect,” said security researchers Alex Delamotte, Stephen Bromfield, Mary Braden Murphy, and Amey Patne. “In many configurations, this includes service accounts connected to an authentication infrastructure such as Active Directory (AD) or Lightweight Directory Access Protocol (LDAP).”

“This setting allows the appliance to map roles to specific users by retrieving attributes about the connections being analyzed and correlating them with directory information. This is useful when role-based policies are configured and to speed up response to network security alerts detected by the device.”

However, the cybersecurity firm noted that such access could be exploited by attackers who compromise FortiGate devices through known vulnerabilities (such as CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858) or misconfigurations.

In one incident, attackers allegedly compromised a FortiGate appliance in November 2025, created a new local administrator account named “support,” and used it to set four new firewall policies that allowed the account to pass through all zones without restriction.

The threat actor then continued to periodically check the device to ensure it was accessible. This is consistent with Initial Access Brokers (IABs) establishing a foothold and selling to other criminals for financial gain. The next phase of activity, in which the attackers likely extracted configuration files containing encrypted service account LDAP credentials, was detected in February 2026.

SentinelOne said, “There is evidence that the attacker authenticated to AD using plaintext credentials for the fortidcagent service account, suggesting that the attacker decrypted the configuration files and extracted the service account credentials.”

The attackers then leveraged the service account to authenticate into the victim’s environment and register the rogue workstation in AD, allowing deeper access. Following this step, a network scan was initiated, at which point the compromise was detected and further lateral movement was stopped.

In another case investigated in late January 2026, attackers quickly moved from firewall access to deploying remote access tools such as Pulseway and MeshAgent. In addition, the attackers downloaded malware from cloud storage buckets via PowerShell from Amazon Web Services (AWS) infrastructure.

Java malware launched via DLL sideloading was used to exfiltrate the NTDS.dit file and the contents of the SYSTEM registry hive to an external server (‘172.67.196’).[.]232″) via port 443.

“Although the attacker may have attempted to decode passwords from the data, we did not observe any use of such credentials between the collection of the credentials and the containment of the incident,” SentinelOne added.

“NGFW appliances have become ubiquitous because they provide organizations with powerful network monitoring capabilities by integrating firewall security controls with other management functions such as AD,” it added. “However, these devices are high-value targets for attackers with a variety of motivations and skill levels, from state-sponsored espionage attackers to financially motivated attacks such as ransomware.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticlePre-Inca cultures acquired Amazonian parrots hundreds of miles away to use feathers to decorate the dead, new analysis reveals
Next Article Mandiant founder just raised $190 million for autonomous AI agent security startup

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

Madonna features surprise star in Sabrina Carpenter’s ‘Bring Your Love’ video

Discover the Digital Twin That Revolutionizes Online Sales: The Story of Farmasi and a Collaborator Who Changes Everything

Melanie Martinez releases statement praising ex-girlfriend

Trending Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Madonna features surprise star in Sabrina Carpenter’s ‘Bring Your Love’ video

June 15, 2026

Melanie Martinez releases statement praising ex-girlfriend

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.