Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Network Security - Arctic Wolf Warns of Ongoing Attacks Targeting FortiGate Firewall Management Interfaces
Network Security Latest News News & Analysis Security Threat Intelligence Threats and Vulnerabilities

Arctic Wolf Warns of Ongoing Attacks Targeting FortiGate Firewall Management Interfaces

Kirsten DoyleBy Kirsten DoyleMarch 17, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Arctic Wolf has warned the industry about ongoing malicious activity targeting the management interfaces of FortiGate firewall devices, which are exposed to the public internet.  

According to the company, bad actors have been actively exploiting these interfaces since early December last year. While the total extent of the attacks is still being investigated, entities that use these products should review and tighten their security practices immediately. 

Management interfaces on firewalls are a known target for malicious actors trying to gain initial access to company networks. They often lead to ransomware and other malicious acts.  

Arctic Wolf stressed that similar attack patterns have been seen in other high-profile security incidents: 

  • In August 2024, SonicWall disclosed CVE-2024-40766, a vulnerability that enabled unsanctioned access to management and SSL VPN interfaces. This flaw was later used by malefactors to deploy Fog and Akira ransomware. 
  • In November 2024, the security company found a mass exploitation campaign involving CVE-2024-0012 and CVE-2024-9474, vulnerabilities that affected Palo Alto Networks PAN-OS software. 

Limiting Access  

“For all firewall devices, Arctic Wolf strongly recommends restricting firewall management interface access to trusted internal networks as a security best security practice across all firewall configurations, regardless of vendor,” the advisory says. 

Those using Fortinet FortiGate firewalls are urged to follow guidance issued by each vendor for securing and hardening their devices; detailed best practices for system administrators can be found here.  

In addition, Arctic Wolf advises businesses to configure log monitoring on all firewall devices by setting up syslog monitoring to detect anomalous activity as soon as possible. As the company’s investigation of this active threat continues, they are also advised to act quickly to limit their exposure and protect their critical infrastructure. 

Always on the Hunt 

Stefan Hostetler, Lead Threat Intelligence Researcher at Arctic Wolf, says malicious actors are always looking for new sources of financial gain, and the vulnerabilities described here are another way entities can be exposed.  

“The good news in this case is that the patch previously released by Fortinet should cover both vulnerabilities. The latest reports suggest that threat actors are going after the remaining organizations who were unable to apply the patch or harden their firewall configurations when the vulnerability was originally disclosed.” 

He says when known vulnerabilities go unmitigated, bad actors are quick to exploit them. “The threat actor tied to the ransomware campaign described by Forescout appears to be using a familiar set of tools seen in past ransomware activity, while adapting their initial access techniques. When the LockBit 3.0 builder leaked in 2022, numerous groups began using it for their own independent campaigns, and this threat actor appears to be doing the same. Additionally, the structure of the ransom note bears similarities to that of other groups such as the now-defunct BlackCat/ALPHV ransomware variant. This illustrates how the threat actors hiding behind ransomware group names rebrand and adapt as their incentives and alliances evolve over time.” 

Hostetler says entities who have not yet patched this vulnerability should do so as soon as possible and review their firewall security configuration to avoid becoming another statistic of this and other similar campaigns.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Major US telecom providers debut C2 ISAC to counter AI-driven threats

May 26, 20264 Mins Read

FCC Blocks Foreign-Made Routers, Citing National Security Risks

March 26, 20268 Mins Read

Cutting Into Overtime, Not Corners: How Network Automation Drives Business Value

March 13, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}