
FortiGate SSO Flaws Enable Attackers to Compromise AD Credentials and Exfiltrate Sensitive Data
From the Front Linesad compromisefortigatefortigate edgenext-gen firewall (NGFW)workstation security
FortiGate Single Sign-On (SSO) flaws enable attackers to steal device configurations, abuse Active Directory (AD) credentials, deploy remote monitoring and management (RMM) tools, and exfiltrate NTDS files containing sensitive AD data. The intrusions involve compromised service accounts leading to the creation of rogue workstations and deep AD compromise. No specific CVEs, dates, or numerical impact metrics were disclosed in the reported findings. The attacks target FortiGate Edge devices, including Next-Generation Firewalls (NGFWs), and exploit weaknesses in authentication and credential handling. The full scope of affected systems or timelines remains unspecified.