Attackers exploit FortiGate devices to access sensitive network information

2026-03-10T20:51:49Zcbf338adfb4915c5965be4496df9c68c10466a969e72be5021ecee4fe5870813
2fa-phishingapt28aurainspectorbeardshellcisa-kevconfiguration-theftcovenantcredentialsericssonespionageexperience-cloudfbifortigateivanti-epmknown-exploited-vulnerabilitieslaw-enforcement-takedownmisconfigurationomnissa-workspace-onephishing-as-a-servicesalesforcesentinelonesolarwindsthird-party-breachtycoonzoning-phishing-scammer-alerts','russia-linked-operations','mess

What happened

Multiple high-impact cyber incidents and campaigns reported: attackers are exploiting FortiGate devices (vulnerabilities or weak credentials) to steal configuration files containing service-account credentials and network details; Russia-linked APT28 has conducted long-term espionage against Ukrainian forces using BEARDSHELL and COVENANT malware; threat actors are mass-scanning Salesforce Experience Cloud sites with a modified AuraInspector to exploit misconfigurations and exfiltrate data; CISA added multiple flaws (including Ivanti EPM, SolarWinds, and Omnissa Workspace One) to its Known Expl

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
cbf338adfb4915c5965be4496df9c68c10466a969e72be5021ecee4fe5870813
Enrichment time
2026-03-10T20:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.