A quiet but methodical campaign against FortiGate firewalls has drawn the attention of security researchers after attackers were found breaking into internet-exposed management interfaces, rewriting configurations, and siphoning credentials from affected networks. The intrusions are believed to date back to November 2024, giving the threat actors behind them months of unhindered access before the activity surfaced publicly.
According to analysis published by the cybersecurity firm Arctic Wolf, attackers logged into administrative panels on vulnerable firewalls, created new accounts with elevated privileges, and manipulated SSL VPN authentication settings to maintain a persistent foothold. The precise method of initial entry has not been confirmed, but researchers believe it involved a previously unknown vulnerability affecting firmware versions between 7.0.14 and 7.0.16. For organizations trying to assess their own exposure to this kind of attack, reviewing firewall management practices and consulting more information on securing remote access configurations has become an urgent priority rather than a routine task.
How the Intrusion Unfolded
What distinguishes this campaign is the attackers' reliance on the jsconsole interface, a built-in command-line tool within FortiOS, accessed from a limited but unusual set of IP addresses. That pattern suggests more than one actor or group may have participated, whether through shared tooling, a coordinated operation, or an access broker supplying footholds to multiple buyers. Once inside, the intruders altered logging verbosity from "standard" to "more," a change that can obscure or complicate forensic review, before provisioning new super administrator accounts. Those accounts were then used to create as many as six local user profiles per compromised device, folding them into existing groups authorized for SSL VPN access. From there, attackers established encrypted VPN tunnels into victim networks, with connecting traffic traced back to a small cluster of commercial VPS providers - a setup that lends anonymity while mimicking legitimate remote-access behavior.
Fortinet Confirms a Critical Zero-Day
Fortinet has since confirmed the underlying flaw, designated CVE-2024-55591, an authentication bypass vulnerability in FortiOS and FortiProxy carrying a severity score of 9.6 out of 10. The company has linked it directly to the hijacking of management interfaces and subsequent network breaches described in the Arctic Wolf findings. Affected products include FortiOS versions 7.0.0 through 7.0.16, which should be upgraded to 7.0.17 or later; FortiProxy 7.0.0 through 7.0.19, requiring an upgrade to 7.0.20; and FortiProxy 7.2.0 through 7.2.12, which needs version 7.2.13 or above. Fortinet has reiterated long-standing guidance that management interfaces should never be exposed directly to the public internet, recommending instead that access be restricted to trusted internal networks or controlled through dedicated management VLANs.
A Familiar Pattern With Wider Implications
The U.S. Cybersecurity and Infrastructure Security Agency has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating that federal agencies apply remediation by January 21, 2025. This episode fits a recurring pattern in enterprise security: perimeter devices such as firewalls and VPN gateways, designed to protect networks, increasingly become the entry point for attackers when their own administrative interfaces are left reachable from outside. As organizations lean more heavily on remote access infrastructure, the incident is a reminder that the security of the gatekeeper itself - not just the traffic it filters - deserves continuous scrutiny.