Zero-Day Attacks On Firewalls: Fortinet Issues Warning

00:00 / 00:00 Game-Changing SOC Trends In 2026: AI, SOAR & XDR Shifts

Fortinet issues a warning on a new Zero-Day attack on Fortinet FortiGate firewall devices with management interfaces exposed to the public. The campaign began around mid-November 2024 by accessing management interfaces, creating new admin accounts, changing configurations, and bypassing SSL VPN for lateral movement. The threat actors are unknown, and they have taken advantage of this vulnerability to extract credentials using DCSync.

For context, a Zero-Day is an unknown software vulnerability exploited by hackers to gain entry into vulnerable networks, servers, and systems. It is called Zero-Day because it occurs before an organization becomes aware of it, giving them zero days to address the issue.

The firmware devices that were impacted and are still undergoing recovery range between 7.0.14 and 7.0.16, which were released in February and October of 2024.

Also Read: A Critical Vulnerability Rating 10/10 Has Been Confirmed By Microsoft

Fortinet has confirmed that the attacks came in four waves:

  • Scanning and reconnaissance.
  • Configuration changes (e.g., enabling new admin accounts).
  • Creating local user accounts with VPN access.
  • Credential extraction for lateral movement.

Currently, Fortinet has given its response to update its firmware and minimize public-facing interfaces to control future threats.

Simply put, a fault in a firewall was used to gain bigger access, create an entryway for hackers, and move deeper into their networks. As a SOC service provider, we’d agree no security is too much security. If you harbor confidential data that can put an entire organization or a chain of clients at risk, then having 24/7 SOC monitoring can save you potentially costly losses and lawsuits.

Leave a Reply

Your email address will not be published. Required fields are marked *

The Author

Sreekanth

SOC Manager

Sreekanth is the SOC Manager at Secucenter with over 12 years of experience in cybersecurity and IT operations. His expertise includes infrastructure management, security implementation, security monitoring, threat detection, incident response, and SOC operations across on-premises, hybrid, and cloud environments. He focuses on building effective SOC processes and teams that combine people, processes, and technology to deliver reliable and customer-focused security operations.

FEATURED INSIGHTS

Security Intelligence
Hub

The True Cost of 24/7 In-House Cybersecurity Operations in 2026

Your business is surrounded by sharks waiting to take a bite of...

Read more ›

What the CDSL Malware Attack Teaches Organizations About VAPT?

Most organizations believe that completing an annual Vulnerability Assessment and Penetration Testing...

Read more ›

The Human Firewall: What Kevin Mitnick Can Teach Us About Financial Fraud Today

The world's most famous hacker never needed to "hack" much Kevin Mitnick...

Read more ›

Stop guessing where you're exposed.
Talk to a senior analyst this week.

Get a Free Security Audit

Protect Your Business Today To Scale Tomorrow

Most breaches begin with a gap no one was watching. Tell us what you're protecting and our SOC analysts will pressure-test your defenses and show you exactly where you stand.

Phone

+1 607 360 5504

Sales Office - United States

651, N Broad St, Middletown
Delaware-19709

Operations Center- India

Level 17, TransAsia Cyber Park
Kochi, Kerala-682030

Data privacy notice. All submissions are protected via TLS 1.3 encryption in transit and processed within our secure, air-gapped data environment. We never resell your data.