Arctic Wolf detected a new automated attack campaign targeting Fortinet FortiGate devices starting January 15, 2026. Attackers exploited SSO accounts to make unauthorized firewall configuration changes, create persistence accounts, grant VPN access, and exfiltrate configurations. The activity resembles a previous December 2025

4m read time From arcticwolf.com
Post cover image
Table of contents
Previously Disclosed SSO VulnerabilitiesIndicators of CompromiseRecommendations

Sort: