Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

DEAD#VAX malware campaign deploys AsyncRAT via VHD phishing files hosted on IPFS

China-linked Amaranth-Dragon exploits WinRAR flaws for espionage

European Commission launches €605 million Africa Initiative IV

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Fortinet Verifies Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls
Identity

Fortinet Verifies Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls

userBy userJanuary 23, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananJanuary 23, 2026Network security/vulnerabilities

Fortinet has officially confirmed that it is working to fully resolve the FortiCloud SSO authentication bypass vulnerability following reports of new exploit activity on fully patched firewalls.

“Over the past 24 hours, we have identified a number of cases in which devices were fully upgraded to the latest release at the time of the attack, suggesting a new attack vector,” Carl Windsor, Fortinet’s chief information security officer, said in a post Thursday.

This activity essentially mounts a bypass of the patches introduced by network security vendors to address CVE-2025-59718 and CVE-2025-59719. This could allow unauthenticated bypass of SSO login authentication via a crafted SAML message if the FortiCloud SSO feature is enabled on the affected device. This issue was originally resolved by Fortinet last month.

However, earlier this week, reports emerged of new activity in which malicious SSO logins on FortiGate appliances were logged to administrator accounts on devices that had been patched for these two vulnerabilities. This activity is similar to incidents observed in December, shortly after the publication of CVE-2025-59718 and CVE-2025-59719.

cyber security

This activity includes creating general-purpose accounts for persistence, making configuration changes to allow VPN access to those accounts, and leaking firewall configurations to different IP addresses. The attacker has been observed logging in with accounts named ‘cloud-noc@mail.io’ and ‘cloud-init@mail.io’.

As a mitigation measure, the company is asking you to take the following steps:

Apply local-in policies to restrict management access to edge network devices over the Internet. Disable FortiCloud SSO login by disabling ‘admin-forticloud-sso-login’.

“It is important to note that while we have only seen FortiCloud SSO abuse at this time, this issue applies to all SAML SSO implementations,” Fortinet said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDETANGLE project supports EU cybersecurity regulations
Next Article Tesla discontinues Autopilot to promote full self-driving software
user
  • Website

Related Posts

DEAD#VAX malware campaign deploys AsyncRAT via VHD phishing files hosted on IPFS

February 4, 2026

China-linked Amaranth-Dragon exploits WinRAR flaws for espionage

February 4, 2026

Orchid Security brings continuous identity observability to enterprise applications

February 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

DEAD#VAX malware campaign deploys AsyncRAT via VHD phishing files hosted on IPFS

China-linked Amaranth-Dragon exploits WinRAR flaws for espionage

European Commission launches €605 million Africa Initiative IV

Orchid Security brings continuous identity observability to enterprise applications

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.