Close Menu
    What's Hot

    This amazing ‘Akira’ bike is the latest entry in the wonderful shadow industry of banned Lego sets

    Cuba to Trump: We’re Open for Business

    KKR profits soar as it cashes in record amount of private equity bets

    Facebook X (Twitter) Instagram
    Trending
    • This amazing ‘Akira’ bike is the latest entry in the wonderful shadow industry of banned Lego sets
    • Cuba to Trump: We’re Open for Business
    • KKR profits soar as it cashes in record amount of private equity bets
    • A ‘Credibility Shock’ Looms Over the Fed
    • OpenAI’s Hacking Debacle Was a Human Mistake
    • Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
    • How to Watch Two Summer Meteor Showers Peak On the Same Night
    • Pope Leo Says He Hopes to Visit U.S. Within ‘Next Couple of Years’
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials

    adminBy adminMarch 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMar 10, 2026Network Security / Vulnerability

    FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials

    Cybersecurity researchers are calling attention to a new campaign where threat actors are abusing FortiGate Next-Generation Firewall (NGFW) appliances as entry points to breach victim networks. 

    The activity involves the exploitation of recently disclosed security vulnerabilities or weak credentials to extract configuration files containing service account credentials and network topology information, SentinelOne said in a report published today. The security outfit said the campaign has singled out environments tied to healthcare, government, and managed service providers.

    “FortiGate network appliances have considerable access to the environments they were installed to protect,” security researchers Alex Delamotte, Stephen Bromfield, Mary Braden Murphy, and Amey Patne said. “In many configurations, this includes service accounts which are connected to the authentication infrastructure, such as Active Directory (AD) and Lightweight Directory Access Protocol (LDAP).”

    Cybersecurity

    “This setup can enable the appliance to map roles to specific users by fetching attributes about the connection that’s being analyzed and correlating with the Directory information, which is useful in cases where role-based policies are set or for increasing response speed for network security alerts detected by the device.”

    However, the cybersecurity company noted that such access could be exploited by attackers who break into FortiGate devices through known vulnerabilities (e.g., CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858) or misconfigurations.

    In one incident, the attackers are said to have breached a FortiGate appliance in November 2025 to create a new local administrator account named “support” and used it to set up four new firewall policies that allowed the account to traverse all zones without any restrictions.

    The threat actor then kept periodically checking to ensure the device was accessible, an action consistent with an initial access broker (IAB) establishing a foothold and selling it to other criminal actors for monetary gain. The next phase of the activity was detected in February 2026 when an attacker likely extracted the configuration file containing encrypted service account LDAP credentials.

    “Evidence demonstrates the attacker authenticated to the AD using clear text credentials from the fortidcagent service account, suggesting the attacker decrypted the configuration file and extracted the service account credentials,” SentinelOne said.

    The attacker then leveraged the service account to authenticate to the victim’s environment and enroll rogue workstations in the AD, allowing them deeper access. Following this step, network scanning was initiated, at which point the breach was detected, and further lateral movement was halted.

    Cybersecurity

    In another case investigated in late January 2026, attackers swiftly moved from firewall access to deploying remote access tools like Pulseway and MeshAgent. In addition, the threat actor downloaded malware from a cloud storage bucket via PowerShell from Amazon Web Services (AWS) infrastructure.

    The Java malware, launched via DLL side-loading, was used to exfiltrate the contents of the NTDS.dit file and SYSTEM registry hive to an external server (“172.67.196[.]232”) over port 443.

    “While the actor may have attempted to crack passwords from the data, no such credential usage was identified between the time of credential harvesting and incident containment,” SentinelOne added.

    “NGFW appliances have become ubiquitous because they provide strong network monitoring capabilities for organizations by integrating security controls of a firewall with other management features, such as AD,” it added. “However, these devices are high-value targets for actors with a variety of motivations and skill levels, from state-aligned actors conducting espionage to financially motivated attacks such as ransomware.”

    account breach Credentials devices Exploited FortiGate Networks service steal
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleAre We Facing an AI Nightmare? by Raghuram G. Rajan
    Next Article U.S. military contractor likely built iPhone hacking tools used by Russian spies in Ukraine
    admin
    • Website

    Related Posts

    Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

    July 30, 2026

    Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

    July 30, 2026

    Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

    July 30, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    This amazing ‘Akira’ bike is the latest entry in the wonderful shadow industry of banned Lego sets

    Cuba to Trump: We’re Open for Business

    KKR profits soar as it cashes in record amount of private equity bets

    A ‘Credibility Shock’ Looms Over the Fed

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by