Attackers exploit FortiGate devices to access sensitive network information
2026-03-10T20:51:49Z•cbf338adfb4915c5965be4496df9c68c10466a969e72be5021ecee4fe5870813
2fa-phishingapt28aurainspectorbeardshellcisa-kevconfiguration-theftcovenantcredentialsericssonespionageexperience-cloudfbifortigateivanti-epmknown-exploited-vulnerabilitieslaw-enforcement-takedownmisconfigurationomnissa-workspace-onephishing-as-a-servicesalesforcesentinelonesolarwindsthird-party-breachtycoonzoning-phishing-scammer-alerts','russia-linked-operations','mess
What happened
Multiple high-impact cyber incidents and campaigns reported: attackers are exploiting FortiGate devices (vulnerabilities or weak credentials) to steal configuration files containing service-account credentials and network details; Russia-linked APT28 has conducted long-term espionage against Ukrainian forces using BEARDSHELL and COVENANT malware; threat actors are mass-scanning Salesforce Experience Cloud sites with a modified AuraInspector to exploit misconfigurations and exfiltrate data; CISA added multiple flaws (including Ivanti EPM, SolarWinds, and Omnissa Workspace One) to its Known Expl
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- cbf338adfb4915c5965be4496df9c68c10466a969e72be5021ecee4fe5870813
- Enrichment time
- 2026-03-10T20:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.