Wednesday , April 16 2025
FortiGate Firewall

Hackers Allegedly Advertise To Sell FortiGate Firewall 0-Day Exploit

A threat actor is reportedly advertised to sell a zero-day exploit for Fortinet’s FortiGate firewalls on a dark web forum.

The exploit claims allow attackers to remotely execute code and access configurations on FortiOS without needing credentials, potentially taking control of vulnerable devices.

Bengaluru firm got ransomware attack, Hacker demanded $70,000

Bengaluru's Whiteboard Technologies Pvt Ltd was hit by a ransomware attack, with hackers demanding a ransom of up to $70,000...
Read More
Bengaluru firm got ransomware attack, Hacker demanded $70,000

MITRE warns: U.S. Govt. Funding for MITRE’s CVE Ends Today

MITRE Vice President Yosry Barsoum warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness...
Read More
MITRE warns: U.S. Govt. Funding for MITRE’s CVE Ends Today

PwC exits more than a dozen countries in push to avoid scandals: FT reports

PwC has ceased operations in more than a dozen countries that its global bosses have deemed too small, risky or...
Read More
PwC exits more than a dozen countries in push to avoid scandals: FT reports

Australian Cyber Security Centre Alert for Fortinet Products

The Australian Cyber Security Centre (ACSC) has alerted technical users in both private and public sectors about ongoing exploitation of...
Read More
Australian Cyber Security Centre Alert for Fortinet Products

Top 10 Malware Threats of the Week: Reports ANY.RUN

Cybersecurity platform ANY.RUN recently reported the top 10 malware threats of the week, highlighting a surge in activity for information...
Read More
Top 10 Malware Threats of the Week: Reports ANY.RUN

Hackers Exploit Ivanti VPN Vulns 12 Countries to Infiltrate Multiple Orgs

In late March, TeamT5 found that a China-linked APT group exploited a critical vulnerability in Ivanti Connect Secure VPN appliances,...
Read More
Hackers Exploit Ivanti VPN Vulns 12 Countries to Infiltrate Multiple Orgs

Hackers Allegedly Advertise To Sell FortiGate Firewall 0-Day Exploit

A threat actor is reportedly advertised to sell a zero-day exploit for Fortinet's FortiGate firewalls on a dark web forum....
Read More
Hackers Allegedly Advertise To Sell FortiGate Firewall 0-Day Exploit

New Security Companies Who Are Exploring the Bangladeshi Market 

BlackHat Asia-2025 was held for four days at the Marina Bay Convention Center in Singapore in early April. Infosecbulletin covered...
Read More
New Security Companies Who Are Exploring the Bangladeshi Market 

Hackers retain access to patched FortiGate VPNs using symlinks

Recent incidents continue to bring this into focus with active exploitations of known vulnerabilities as investigations by Fortinet have discovered...
Read More
Hackers retain access to patched FortiGate VPNs using symlinks

CISA Releases Ten Industrial Control Systems Advisories

The Cybersecurity and Infrastructure Security Agency (CISA) has released ten new advisories regarding Industrial Control Systems (ICS) to highlight serious...
Read More
CISA Releases Ten Industrial Control Systems Advisories

Cybersecuritynews reported the forum post observed by ThreatMon boasts extensive capabilities, including access to sensitive configuration files extracted from compromised devices. These files purportedly contain:

Local user credentials: Encrypted passwords stored in local_users.json.
Admin account details: Permissions and trust relationships documented in admin_accounts.json.
Two-factor authentication (2FA) status: Information on FortiToken configurations (two_factor.json).
Firewall policies and network configurations: Complete rule sets, NAT mappings, internal IP assets, and address groups.

This data could enable attackers to evade security, access networks, and launch additional attacks. The exploit specifically targets FortiOS versions with known authentication bypass vulnerabilities, a common problem in Fortinet products.

Fortinet recently announced a critical vulnerability (CVE-2024-55591) that allows attackers to obtain super-admin privileges via specially crafted requests. This flaw affected FortiOS versions 7.0.0 to 7.0.16 and FortiProxy versions 7.0.0 to 7.0.19 and 7.2.0 to 7.2.12.

If the hacker’s claim is true, the advertised zero-day exploit poses significant risks to organizations using Fortinet firewalls.

Unauthorized Access: Attackers could gain administrative control over devices, modify configurations, and extract sensitive data.
Network Compromise: Exploited firewalls could serve as entry points for network lateral movement.
Data Breaches: Leaked credentials and configuration files could lead to exposure to confidential information.
Operational Disruption: Altered firewall policies may disrupt normal network operations or create vulnerabilities for future attacks.

Fortinet has repeatedly encouraged users to apply patches quickly to address product vulnerabilities. They’ve issued advisories on indicators of compromise (IOCs) and recommended security measures like disabling HTTP/HTTPS admin interfaces and restricting access with local policies.

Source: Cybersecuritynews, Threatmon, the420.in

New Security Companies Who Are Exploring the Bangladeshi Market 

Check Also

OpenAI

OpenAI Offering $100K Bounties for Critical Vulns

OpenAI has increased its maximum bug bounty payout to $100,000, up from $20,000, to encourage …

Leave a Reply

Your email address will not be published. Required fields are marked *