Wednesday , June 24 2026
600

Amazon Report
Hacker compromised 600+ FortiGate devices in 55 countries

Amazon Threat Intelligence observed that a Russian-speaking hacker used generative AI services to compromise over 600 FortiGate devices in 55 countries between January 11 and February 18, 2026. The attack did not exploit FortiGate vulnerabilities but targeted exposed management ports and weak, single-factor authentication, enabling a less-skilled attacker to exploit these security weaknesses widely.

The threat actor is using various commercial GenAI services to execute and expand familiar attack techniques, even with limited technical skills. Amazon Threat Intelligence shares these insights to help the security community to combat these threats.

LastPass says hackers stole customer data via Klue, supply chain breach

LastPass has reported a security issue with its vendor, Klue. This incident allowed an attacker unauthorized access to customer data....
Read More
LastPass says hackers stole customer data via Klue, supply chain breach

New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

Researchers at cybersecurity firm Paradigm Shift found a new flaw called usbliter8. This flaw can get around main boot protections...
Read More
New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

CJ Moses, CISO of Amazon Integrated Security, said the compromised firewalls were observed across South Asia, Latin America, the Caribbean, West Africa, Northern Europe, and Southeast Asia, among other regions.

An AI-powered hacking campaign

The threat actor scanned for FortiGate management interfaces exposed online on ports 443, 8443, 10443, and 4443. They targeted these services opportunistically, not focusing on specific industries.

Once breached, the threat actor extracted the device’s configuration settings, which include:

SSL-VPN user credentials with recoverable passwords
Administrative credentials
Firewall policies and internal network architecture
IPsec VPN configurations
Network topology and routing information

These configuration files were then processed and decrypted using automated tools.

“Following VPN access to victim networks, the threat actor deploys a custom reconnaissance tool, with different versions written in both Go and Python,” explained Amazon.

“Analysis of the source code reveals clear indicators of AI-assisted development: redundant comments that merely restate function names, simplistic architecture with disproportionate investment in formatting over functionality, naive JSON parsing via string matching rather than proper deserialization, and compatibility shims for language built-ins with empty documentation stubs.”

“While functional for the threat actor’s specific use case, the tooling lacks robustness and fails under edge cases—characteristics typical of AI-generated code used without significant refinement.”

by gathering information on the networks, sorting them by size, checking for open ports with the gogo scanner, finding SMB hosts and domain controllers, and using Nuclei to scan for HTTP services.

The campaign targeted Veeam Backup & Replication servers with custom PowerShell scripts and tools for credential extraction, looking to exploit vulnerabilities.

On one of the servers found by Amazon (212[.]11.64.250), the threat actor hosted a PowerShell script named “DecryptVeeamPasswords.ps1” that was used to target the backup application.

As Amazon explains, threat actors often target backup infrastructure before deploying ransomware to prevent the restoration of encrypted files from backups. The threat actors’ “operational notes” also contained multiple references to trying to exploit various vulnerabilities, including CVE-2019-7192 (QNAP RCE), CVE-2023-27532 (Veeam information disclosure), and CVE-2024-40711 (Veeam RCE).

The company advises FortiGate admins to avoid exposing management interfaces online, enable MFA, use different VPN passwords from Active Directory accounts, and strengthen backup systems. Recently, Google noted that cybercriminals are misusing Gemini AI in various stages of their attacks, similar to Amazon’s findings.

Indicators of compromise (IOCs)

IOC Value IOC Type First Seen Last Seen Annotation
212[.]11.64.250 IPv4 1/11/2026 2/18/2026 Threat actor infrastructure used for scanning and exploitation operations
185[.]196.11.225 IPv4 1/11/2026 2/18/2026 Threat actor infrastructure used for threat operations

Check Also

Texas

Texas data breach exposes 3 million driver’s licenses

The Texas Parks and Wildlife Department (TPWD) revealed a data leak at its license system …