Fortinet has uncovered a sophisticated post-exploitation technique used by a threat actor to maintain unauthorized access to FortiGate devices, even after initial vulnerabilities were patched.
The discovery, detailed in a recent Fortinet investigation, highlights the persistent risks of unpatched systems and underscores the company’s commitment to responsible transparency and rapid response.
According to Fortinet’s findings, the threat actor exploited known vulnerabilities previously identified as FG-IR-22-398, FG-IR-23-097, and FG-IR-24-015—to gain access to FortiGate devices.
In a novel approach, the actor created a symbolic link between the user and root filesystems in a folder serving language files for SSL-VPN. This allowed read-only access to device files, including configurations, without triggering detection.
Alarmingly, the link could persist even after devices were updated to address the original vulnerabilities, leaving systems exposed.
Fortinet’s investigation, supported by internal telemetry and third-party collaboration, confirmed that the activity was not limited to a specific region or industry. Customers who never enabled SSL-VPN on their devices are unaffected by this issue.
Upon identifying the technique, Fortinet activated its Product Security Incident Response Team (PSIRT) and implemented immediate mitigations. These include:
Fortinet recommends that all customers impacted or not upgrade to the patched versions and follow recovery steps outlined in its community resources.
The company emphasized the urgency of timely updates, citing its 2H 2023 Global Threat Landscape Report, which found that threat actors exploit known vulnerabilities within an average of 4.76 days of public disclosure.
“This incident reflects the evolving tactics of threat actors and the critical need for robust cyber hygiene,” said Carl Windsor, a Fortinet spokesperson to Cyber Security News “We’re committed to supporting our customers with proactive solutions and transparent communication to stay ahead of these threats.”
To bolster defenses, Fortinet has introduced enhanced security features in recent updates, including compile-time hardening, virtual patching, firmware integrity validation, and automated upgrade tools like Uninterrupted Cluster Upgrade and Automatic Patch Upgrades.
The company continues to advocate for industry-wide collaboration to strengthen cybersecurity standards.
Customers seeking guidance can access Fortinet’s best practice resources or contact the company directly for support. With over 40,000 vulnerabilities recorded in 2024, according to NIST data, Fortinet’s message is clear: staying vigilant and up to date is the best defense against today’s cyber threats.
The founder of WatchTowr reported that backdoor deployments linked to the Fortinet exploit are being identified across their client base—including organizations deemed critical infrastructure. He urged the community to take Fortinet’s alert seriously, while questioning the industry’s current response process to high-profile vulnerabilities in critical systems.
CISA’s April 11 advisory reinforces Fortinet’s guidance, urging administrators to:
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Security News Updates!
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…