Tag
high
threat
Fortinet FortiOS CVE-2025-68686 Sensitive Information Exposure Bypass
1 TTP 3 CVEs 4 IOCsA remote unauthenticated attacker can exploit CVE-2025-68686 in Fortinet FortiOS to bypass a previously applied patch, allowing sensitive information exposure and enabling persistence post-exploitation, provided the product was already compromised at the filesystem level via another vulnerability.
exploited
PoC
FortiOS +7
fortinet
vulnerability
cve
exposure
persistence
1t
3c
4i
updated
critical
threat
FortiBleed Campaign: 73,932 FortiGate Systems Credentials Exposed
3 rules 9 TTPs 1 IOCA Russian-speaking threat group utilized a large dataset of administrative and VPN credentials, likely sourced from exposed FortiGate configuration files and active credential harvesting, to access government, critical infrastructure, and multinational corporate networks, resulting in widespread data exfiltration.
FortiGate +1
Russian-speaking threat group
credential-theft
fortios
state-sponsored
espionage
data-exfiltration
russian-speaking
critical-infrastructure
government
3r
9t
1i
high
advisory
Fortinet FortiOS Privilege Escalation Vulnerability
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Fortinet FortiOS to escalate their privileges.
FortiOS
privilege-escalation
fortinet
2r
1t