TL;DR

Over 600 FortiGate firewalls were compromised in an AI-augmented cyber attack by a Russian-speaking group.

What happened

['Over 600 internet-exposed FortiGate firewalls across 55 countries were breached.', 'Attackers utilized off-the-shelf generative AI tools to identify and compromise the devices.']

Why it matters for ops

['Generative AI was used to enhance attack vectors and automate discovery of vulnerable firewalls.', 'Lack of proper firewall security practices and exposure to the internet made these devices susceptible to attacks.']

Mitigation

  • Implement strict security policies for internet-facing firewalls.
  • Regularly update and patch all security appliances.

Action items

  • Conduct a thorough audit of exposed network infrastructure.
  • Review and enhance firewall security configurations immediately.

Detection IOCs

  • Unusual outbound traffic from FortiGate devices
  • Anomalies in firewall rule modifications or access logs

Source link

https://go.theregister.com/feed/www.theregister.com/2026/02/23/aws_fortigate_firewalls/