SentinelOne DFIR reported multiple intrusions in which threat actors compromised FortiGate Next-Generation Firewall (NGFW) appliances to gain an initial foothold, then extracted FortiGate configuration files containing service account credentials and network topology data. The activity targeted organizations including healthcare, government, and managed service providers, and in several cases was detected during the lateral-movement stage before full domain compromise. SentinelOne noted that many affected environments lacked sufficient FortiGate logging, limiting defenders’ ability to determine the exact initial access vector and timeline; observed dwell time from perimeter compromise to follow-on internal activity ranged from months to near-immediate escalation.
The intrusions were assessed as enabled by exploitation of recently disclosed Fortinet vulnerabilities and/or weak or misconfigured access controls on edge devices. Reported candidate vulnerabilities included CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858, which could allow unauthorized access and facilitate configuration theft. In one investigated case, attackers created a new local administrator account named "support" on a compromised FortiGate and added permissive firewall policies to allow broad, unrestricted traversal across zones—behavior consistent with establishing durable access and potentially supporting initial access broker (IAB)-style operations that enable deeper Active Directory compromise via stolen directory-connected service accounts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Alongside the disclosure, SentinelOne recommended timely patching, stronger administrative controls, centralized SIEM log collection, and at least 14 days—preferably 60 to 90 days—of log retention. It also advised monitoring for FortiGate and Active Directory abuse because edge appliances often cannot run EDR tools.
SentinelOne assessed on March 10, 2026 that the two investigated incidents do not currently appear attributable to the same threat actor because their post-compromise tradecraft differed significantly. Both incidents were reported as detected and contained during lateral movement.
In its March 10, 2026 report, SentinelOne said the intrusions were likely enabled by exploitation of CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858, or by opportunistic access using weak administrative credentials. Investigators noted limited FortiGate log retention prevented definitive root-cause determination in some cases.
On March 10, 2026, SentinelOne published findings on multiple early-2026 intrusions affecting healthcare, government, and managed service provider environments. The report said attackers abused vulnerable or weakly protected FortiGate appliances to obtain configuration data containing service account credentials and network topology information.
In February 2026, the actor from the first incident exfiltrated the FortiGate configuration file, decrypted embedded LDAP service account credentials, and used them to authenticate to Active Directory. The attacker then joined rogue workstations to the domain and conducted scanning and password spraying before being stopped.
In a separate incident in January 2026, attackers used FortiGate access to pivot quickly into the Windows domain, deployed Pulseway and MeshAgent, delivered a weaponized Java payload via DLL side-loading, and used PsExec to spread. They staged and likely exfiltrated NTDS.dit and the SYSTEM hive from domain controllers during the intrusion.
In one intrusion beginning in November 2025, an attacker gained access to a FortiGate device, created a new local administrator account, and modified firewall policies to remove access restrictions. SentinelOne later assessed this actor may have been functioning as an initial access broker.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcesentinelone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.