Fortinet warns that threat actors use a post-exploitation technique that helps them maintain read-only access to previously compromised FortiGate VPN devices even after the original attack vector was ...
Fortinet customers who have not yet patched a critical authentication bypass vulnerability that the company disclosed in February might want to get to it quickly. CVE-2025-24472 enables allow remote ...
Attackers may have exploited a flaw in Fortinet's FortiOS SSL-VPN in "a limited number of cases" that affected users in government, manufacturing, and critical infrastructure sectors. Exploitation of ...