Attackers exploit FortiGate devices to access sensitive network info


Attackers exploit FortiGate devices to access sensitive network information

Pierluigi Paganini
March 10, 2026

Attackers are exploiting FortiGate devices to breach networks and steal configuration data containing service account credentials and network details.

SentinelOne researchers warn that attackers are exploiting vulnerabilities or weak credentials in FortiGate devices to gain initial access to corporate networks. Once inside, they extract configuration files that may contain service account credentials and information about the internal network structure. The campaign appears to target sectors such as healthcare, government agencies, and managed service providers.

“Throughout early 2026, SentinelOne’s® Digital Forensics & Incident Response (DFIR) team has responded to several incidents where FortiGate Next-Generation Firewall (NGFW) appliances have been compromised to establish a foothold into the targeted environment.” states SentinelOne. “Each incident was detected and stopped during the lateral movement phase of the attack.”

FortiGate appliances, often integrated with AD and LDAP, allow role mapping and fast response for network alerts. Threat actors have abused this access by targeting CVE-2025-59718 and CVE-2025-59719, exploiting SSO signature validation flaws to gain unauthenticated admin access. CVE-2026-24858 allowed attackers to log in through FortiCloud SSO. Once inside, they can extract configuration files containing service accounts, while others exploit weak credentials without needing a vulnerability.

In one case analyzed by Sentinel One, attackers created local admin accounts, modified firewall policies, and periodically checked access before extracting configuration files containing encrypted LDAP service account credentials. These were decrypted to authenticate to Active Directory and enroll rogue workstations, allowing deeper network access.

In another incident, attackers created admin accounts, deployed Pulseway and MeshAgent RMM tools, and used PowerShell and DLL side-loading to execute malware. They staged malicious payloads on cloud storage (Google Cloud, AWS S3), ran tasks to maintain persistence, and used PsExec to move laterally.

The attackers made a backup of the main domain controller, took the NTDS.dit file and SYSTEM registry data, compressed them, and uploaded them to their servers. After the incident was contained, no further misuse of accounts was seen.

Next-generation firewalls (NGFWs), like FortiGate, are widely used because they combine strong network security with features like Active Directory integration. This makes them high-value targets for attackers, from state-sponsored espionage groups to financially motivated criminals. Recent research shows that even less skilled actors can now exploit these devices more easily using AI tools like large language models (LLMs), which provide guidance on navigating networks and extracting sensitive data.

Organizations should secure NGFWs by enforcing strong administrative controls, keeping software patched, and maintaining adequate log retention (at least 14–90 days). Logs should be sent to a SIEM system to detect anomalies, track unauthorized account creation, monitor for configuration access, spot malware or C2 traffic, preserve evidence, and enable automated responses to neutralize threats quickly.

“Organizations should consider that FortiGate and other edge devices typically do not permit security software to be installed on the appliance, such as endpoint detection and response (EDR) tools. The best defense for these appliances is to apply strong administrative access controls and to keep the software patched to prevent exploitation.” concludes the report. “Further, both of these investigations were hindered by insufficient FortiGate log retention. Organizations should ensure they have at least 14 days of log retention on NGFW appliances like FortiGate, though 60-90 days is much better when possible.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Fortinet)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Spotify aims to provide a consistent listening experience that uses minimal data. As a result, your audio quality might be less than ideal, especially if you’re using a pair of high-fidelity headphones or high-end speakers. Here’s how to fix that.

Switch audio streaming quality to Very High or Lossless

The default audio streaming quality in both the mobile and desktop Spotify apps is set to Automatic, which usually keeps the audio quality at Normal, which is only 96 Kbps. Even though Spotify uses the Ogg Vorbis codec, which is superior to MP3, OGG files exhibit slight (but noticeable) digital noise, poor bass detail, dull treble, and a narrow soundstage at 96 Kbps.

Even worse, Spotify is aggressive about adjusting the automatic bitrate. Even though 4G is more than fast enough to stream high-quality OGG files, even with a weak signal, Spotify may still drop the quality to Low, which has a bitrate of just 24 Kb/s. You will notice such a sharp drop in quality, even on a pair of bottom-of-the-barrel headphones.

To rectify this, open the Spotify app, tap your user image, open “Settings and privacy,” and tap the “Media Quality” menu. Once there, set Wi-Fi streaming quality and cellular streaming quality to “Very high” or “Lossless.”

I recommend setting cellular streaming quality to Very high and reserving Lossless for Wi-Fi, since lossless streaming is very data-intensive. One hour of streaming lossless files can take up to 1GB of data, as well as a good chunk of your phone’s storage, because Spotify caches files you’re frequently streaming. Besides, you’ll struggle to notice the difference unless you’re listening to music on a wired pair of high-end headphones or speakers; wireless connection just doesn’t have the bandwidth needed to convey the full fidelity of Spotify lossless audio.

You might opt for High quality if you have a capped data plan, but I recommend doing so only if you stream hours upon hours’ worth of music every single day over a cellular network. For instance, I burn through about 8 GB of data per month on average while streaming about two hours of very high-quality music over a cellular network each day.

Illustration of a headphone with various music icons around.


How Audio Compression Works and Why It Can Affect Your Music Quality

Feeling the squeeze when listening to your favorite song?

Set audio download quality to Very high or Lossless

If you tend to download songs and albums for offline listening, you should also set the audio download quality to “Very high” or “Lossless.” This setting is located just under the audio streaming quality section.

The audio download quality menu in Spotify's mobile app.

If you’ve got enough free storage on your phone, opt for the latter, but if you’d rather save storage space, set it to Very high. You’ll hardly hear the difference, but lossless files are about five times larger than the 320 Kb/s OGG files Spotify offers at its Very high quality setting, and they can quickly fill up your phone’s storage.

Adjust video streaming quality at your discretion

The last section of the Media quality menu is Video streaming quality. This sets the quality of video podcasts and music videos available for certain songs. Since I care about neither, I set it to “Very high” on Wi-Fi and “Normal” on cellular, but you should tweak the two options at your discretion because songs sound notably better at higher video streaming quality levels.

If you often watch videos over cellular and have unlimited data, feel free to toggle video quality to very high.

Make sure Data Saver mode is disabled

Even if your audio quality is set to Very high or Lossless, Spotify will switch to low-quality streaming if the app’s Data saver mode is enabled. This option is located in the Data saving and offline menu. Open the menu, then set it to “Always off,” or choose “Automatic” to have Spotify’s Data Saver mode kick in alongside your phone’s Data Saver mode.

You can also enable volume normalization and play around with the built-in equalizer

Spotify logo in the center of the screen with an equalizer in front. Credit: Lucas Gouveia / How-To Geek

Last but not least, there are two additional features you can play with to improve your listening experience. The first is volume normalization, which sets the same loudness for every track you’re listening to. This can be handy because different albums are mastered at different loudness levels, with newer music usually being louder.

Since I’m an album-oriented listener, I keep the option disabled. I can just play an album and set the audio volume accordingly, and I don’t really mind louder songs when listening to playlists, artists, or song radios.

But if you can’t stand one song being quiet and the next rattling the windows, visit the Playback menu, enable “Volume normalization,” and set it to “Quiet” or “Normal.” The “Loud” option can digitally compress files, and neither Spotify nor I recommend using it. This also happens with “Quiet” and “Normal,” since both adjust the decibel level of the master recording for each song, but the compression level is much lower and extremely hard to notice.

Before I end this, I should also mention that you can access the equalizer directly from the Spotify app, where you can fine-tune your music listening experience or pick one of the available equalizer presets. If your phone has a built-in equalizer, Spotify will open it; if it doesn’t, you can use Spotify’s. On my phone (a Samsung Galaxy S21 FE), I can only use One UI’s built-in equalizer.

To open the equalizer, open “Playback,” then hit the “Equalizer” button. Now you can equalize your audio to your heart’s content.


Adjusting just a few settings can have a drastic impact on your Spotify listening experience. If you aren’t satisfied with Spotify’s sound quality, make sure to adjust the audio before jumping ship. You should also check the sound quality settings from time to time, as Spotify can reset them during app updates.​​​​​​​

Three phones with a Spotify screen and the logo in the center.


These 8 Spotify Features Are My Favorite Hidden Gems

Look for these now.



Source link