Truesec reported that attackers exploited FortiGate FortiCloud SSO vulnerabilities CVE-2025-59718 and CVE-2025-59719 to gain unauthorized administrative access to vulnerable firewalls, provided FortiCloud SSO was enabled and the management interface was reachable. Using a valid FortiCloud account, the attackers generated a malicious SAML assertion accepted by the device, allowing them to take control of the firewall and extract its configuration.
Investigations found the stolen configurations contained high-value secrets, including SSL VPN credentials and Active Directory integration accounts, which attackers used to modify VPN policies and NAT behavior, scan internal networks, exfiltrate data, and deploy ransomware through the Domain Controller. Truesec also described a technique in which attackers loaded a stolen configuration onto a controlled FortiGate device and downgraded FortiOS so stored passwords were re-encrypted with a weaker scheme, enabling rapid recovery of plaintext credentials and accelerating lateral movement toward full domain compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After gaining broader access, attackers performed network scanning, exfiltrated data, and deployed ransomware, including via the Domain Controller in the cases Truesec examined. The incidents demonstrated progression from firewall compromise to full environment impact.
In the investigated incidents, attackers downloaded firewall configurations from compromised FortiGate devices and used valid SSL VPN credentials found in those files. They also modified VPN-related firewall policies and NAT behavior to support further intrusion.
Truesec described a technique in which attackers load a stolen configuration onto a FortiGate device and downgrade FortiOS so stored passwords are re-encrypted with an older, weaker scheme. This enables rapid recovery of plaintext credentials from stolen configurations.
Truesec CSIRT reported analyzing multiple incidents involving exploitation of FortiCloud SSO vulnerabilities CVE-2025-59718 and CVE-2025-59719, which allowed unauthorized administrative access to vulnerable FortiGate devices. The cases showed that compromise of a perimeter device could be escalated into broader environment compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcetruesec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.