Skip to content
Threat Feed

Product

FortiGate

15 briefs RSS
high advisory

Cross-Telemetry Correlation of Endpoint and Network Security Alerts

Detection engineering logic that correlates Elastic Defend endpoint alerts with network security events from PAN-OS, FortiGate, and Suricata to identify potentially compromised hosts based on multi-source telemetry.

Elastic Defend +5 correlation multi-datasource network-security endpoint-security phishing email-security
3t
medium advisory

Detection of Anomalous SOCKS Proxy Traffic via FortiGate Integration

This detection leverages cross-platform correlation between FortiGate network application logs and endpoint telemetry to identify processes acting as SOCKS proxies for potential command and control obfuscation.

FortiGate command-and-control proxy network-security cross-platform
1t updated
medium threat

Adversary Use of RAR and PowerShell Downloads for Tooling Delivery

Adversaries, including FIN7, utilize the downloading of RAR archives and PowerShell scripts from external sources to retrieve encoded or encrypted payloads to facilitate initial access and lateral movement.

PAN-OS +1 FIN7 +2 command-and-control ingress-tool-transfer network-security
1r 1t
high threat

The Gentlemen Ransomware Group Activity

The Gentlemen ransomware group leverages VPN/firewall exploits to gain initial access, utilizes BYOVD techniques to disable security tools, and propagates ransomware via the NETLOGON share.

FortiGate +5 The Gentlemen
1r 3t
high advisory

ClickFix Campaign Activity

Tracking brief for the ClickFix campaign; individual sightings are folded in as reported.

open source packages +49 campaign clickfix
29i updated
high threat

FortiGate VPN SSL Settings Modified

Detection of FortiGate VPN SSL settings modification, such as authentication rules, linked to observed exploitation campaigns (e.g., CVE-2024-535), which threat actors leverage for persistence and unauthorized access after initial compromise.

exploited FortiGate persistence initial-access network-device
1r 2t
medium advisory

FortiGate User Group Modification Detected

An attacker with initial access to a Fortinet FortiGate firewall may modify existing user groups to establish persistence or elevate privileges, potentially granting unauthorized VPN access to internal networks.

FortiGate fortinet firewall persistence privilege-escalation
1r 2t
medium advisory

FortiGate - New Local User Creation Detection

This brief details the detection of new local user creation on Fortinet FortiGate firewalls, a behavior often leveraged by adversaries for persistence and unauthorized VPN access, underscoring a critical post-exploitation activity for detection engineers.

FortiGate network detection persistence
1r 1t
medium advisory

FortiGate - New Firewall Policy Added

This brief describes a detection for the addition of new firewall policies on Fortinet FortiGate devices, a behavior that can indicate defense impairment or unauthorized network access by a malicious actor.

FortiGate defense-impairment firewall network
1r 1t
medium advisory

Detection of FortiGate Firewall Address Object Addition

This brief details the detection of firewall address objects being added on Fortinet FortiGate devices, a configuration change that, while potentially legitimate, can also indicate post-compromise activity or unauthorized access, especially when tied to vulnerabilities like FG-IR-24-535, enabling threat actors to bypass security controls or facilitate command and control.

FortiGate network-device firewall defense-evasion
1r
critical threat

FortiBleed Campaign: 73,932 FortiGate Systems Credentials Exposed

A Russian-speaking threat group utilized a large dataset of administrative and VPN credentials, likely sourced from exposed FortiGate configuration files and active credential harvesting, to access government, critical infrastructure, and multinational corporate networks, resulting in widespread data exfiltration.

FortiGate +1 Russian-speaking threat group credential-theft fortios state-sponsored espionage data-exfiltration russian-speaking critical-infrastructure government
3r 9t 1i
high advisory

First-Time FortiGate Administrator Login Detected

A user with the Administrator role has successfully logged in to the FortiGate management interface for the first time within the last 5 days, potentially indicating unauthorized access or misconfiguration.

FortiGate initial-access administrator-login
2r 1t
high advisory

Komari Agent Abused as SYSTEM-Level Backdoor

Threat actors are abusing the Komari monitoring agent, a project hosted on GitHub, as a SYSTEM-level backdoor following initial access through compromised VPN credentials and lateral movement via Impacket.

Defender +2 komari backdoor nssm github rat reverse shell
2r 4t 2i
medium advisory

Newly Observed Fortigate Alert

This brief covers a newly observed Fortigate alert rule added to the Elastic detection rules repository, potentially indicating emerging threat activity targeting Fortigate devices.

Fortigate intrusion-detection network-security
2r 7t
high advisory

DNS Kerberos Coercion Attempt Detection

This brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.

PoC Fortinet edge appliances +38 kerberos coercion dns cve-2025-33073
3r 3t 4c 4i updated