Fortinet Releases Advisory on ... Note

Fortinet Releases Advisory on New Post-Exploitation Technique for Known Vulnerabilities

A threat actor is exploiting known Fortinet FortiOS and FortiGate vulnerabilities to create a malicious file. This file grants read-only access to device files, potentially including configurations. Fortinet is aware of this threat and has released updated FortiOS versions. CISA urges administrators to update to these patched versions (7.6.2, 7.4.7, 7.2.11, 7.0.17, 6.4.16). Reviewing device configurations and resetting exposed credentials are also crucial steps. Disabling SSL-VPN is recommended as a temporary mitigation until patching is complete. The malicious file's creation relies on an enabled SSL-VPN. Organizations should promptly report any incidents or suspicious activity to CISA. Further mitigation information is available from Fortinet's community resources. This threat highlights the importance of regular software updates and security best practices.