Hackers are exploiting a new Fortinet firewall bug to breach company networks

Date:

Share post:


Security researchers say malicious hackers have been exploiting a newly discovered vulnerability in Fortinet firewalls to break into corporate and enterprise networks.

In an advisory published Tuesday, security product maker Fortinet confirmed that a critical-rated vulnerability in its FortiGate firewalls, tracked as CVE-2024-55591, is “being exploited in the wild.” 

Fortinet made patches available, but security researchers have warned that hackers have been mass-exploiting the vulnerability as a zero-day — meaning before Fortinet was aware of the vulnerability and made fixes available — since December.

This is the latest example of hackers exploiting a vulnerability in a popular enterprise security product designed to protect corporate networks from intruders. News of the Fortinet bug lands days after it was revealed that attackers are exploiting a separate zero-day flaw in Ivanti VPN servers that allows access to customers’ networks.

Cybersecurity company Arctic Wolf said in a blog post last week that its researchers observed a recent “mass exploitation” campaign affecting Fortinet FortiGate firewall devices with management interfaces exposed to the public internet.

Stefan Hostetler, lead threat intelligence researcher at Arctic Wolf, confirmed to TechCrunch that this observed exploitation is linked to the newly confirmed CVE-2024-55591 vulnerability in Fortinet firewalls. 

Hostetler told TechCrunch that Arctic Wolf had “observed a cluster of intrusions affecting Fortinet devices in the tens,” but notes that this only represents a “limited sample compared to the total actual number of devices that were likely affected.”

“The evidence points to an effort to exploit a large number of devices within a narrow timeframe,” added Hostetler.

When reached by TechCrunch, Fortinet spokesperson Tiffany Curci declined to say how many Fortinet customers were compromised as a result of this hacking campaign, but said that the company was “proactively communicating with customers.”

It’s also unclear who is behind the attacks on Fortinet firewalls, but cybersecurity researcher Kevin Beaumont writes on Mastodon that the vulnerability is “under exploitation by a ransomware operator.” 

Hostetler said that ransomware attacks exploiting the bug are “not off the table,” noting that in previous research, Arctic Fox “observed affiliates of ransomware groups such as Akira and Fog using some of the same network providers to establish VPN connectivity.”

In a brief statement on Tuesday, U.S. cybersecurity CISA urged Fortinet customers to update any affected devices.

In September, Fortinet disclosed a breach involving customer data after an attacker accessed “a limited number of files” stored on a third-party shared cloud drive belonging to the organization.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

SEC sues Elon Musk for allegedly failing to disclose Twitter acquisition on time

The Securities and Exchange Commission filed a lawsuit against Elon Musk on Tuesday over an alleged securities...

Nvidia backs MetAI, a Taiwanese startup that creates AI-powered digital twins

Nvidia has been doubling down on the opportunity to build robotics and other industrial AI applications, with...

Accel doubles down on Sarla Aviation’s ambition to develop electric air taxis in India

Sarla Aviation launched one year ago with a pitch built for India’s congested streets. The electric air...

Elon Musk tweets so much, people bet over $1M weekly to guess how many posts

Will Elon Musk post more than 400 tweets this week? More than 800? Estimate correctly and you...

Biden admin’s final rule banning Chinese connected cars also bars robotaxi testing on US roads

The U.S. Department of Commerce announced a final rule Tuesday that would ban the sale or import...

Nintendo Switch 2 could be announced this week: The rumors (and facts) so far

With CES 2025 finally in the rearview, it’s time to move on to the next round of...

Intel spins off its corporate venture arm, Intel Capital, into a standalone fund

Intel says that it plans to spin off its corporate venture arm, Intel Capital, into a standalone...

DJI Flip is a $439, fully foldable camera drone

Four short months after introducing the truly palm-size Neo, DJI is back with another pint-sized consumer drone....