/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Fortinet confirms a critical remote authentication bypass vulnerability in FortiOS, FortiProxy, and FortiSwitchManager is being exploited; a patch is available

Sergiu Gatlan / BleepingComputer :

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This is at least the third time Fortinet's edge appliances have drawn active-attack disclosures in this coverage: researchers found remote access via a hard-coded password in older firewall builds back in 2016, and hackers were seen hitting Fortinet VPN services alongside Pulse Secure after critical flaws went public in 2019. The throughline is that the perimeter device itself keeps becoming the entry point.

The patch being available is only half the story. When Fortinet patched a major FortiOS bug in June 2022-era coverage, researchers later counted roughly 336K of ~490K affected SSL VPN interfaces still unpatched — so an actively exploited auth bypass today lands on an installed base with a demonstrated lag problem. Two years on, the same vendor would disclose a FortiManager API flaw exploited in 0-day attacks to steal sensitive files, extending the pattern from firewalls to management infrastructure.

First-order effects

  • Any organization running internet-facing FortiOS, FortiProxy, or FortiSwitchManager is exposed right now to an authentication bypass attackers are already using, making the patch an emergency change rather than routine maintenance.
  • Fortinet's incident response and support teams absorb the load of customers racing to inventory which of the three affected products sit on their perimeter.

Second-order effects

  • Attackers shift to scanning for stragglers who miss the patch window — the same dynamic that left hundreds of thousands of Fortinet SSL VPN interfaces open after a fix existed, and that saw VPN flaws weaponized within days of public disclosure in 2019.
  • Rival appliance vendors face customer questions about their own authentication paths, because every confirmed bypass in one vendor's perimeter stack becomes a due-diligence data point in competitor renewals.

Third-order effects

  • If the cycle repeats — disclosed flaw, available patch, slow installed-base uptake — buyers will increasingly treat a vendor's exploit-and-patch track record as a procurement criterion rather than a post-breach surprise, favoring vendors whose devices can be re-secured quickly.
  • Repeated compromises of the security perimeter itself erode the assumption that the appliance is the trusted layer, pushing architectures toward assuming edge devices are attacker-reachable and segmenting accordingly.

The trend: Internet-facing security appliances are consolidating into attackers' preferred entry point, with each vendor's patch cadence losing ground to its own installed base's update lag.

Discussion

  • @gossithedog Kevin Beaumont on x
    Fortinet have gone live with details now. It is indeed a zero day. They're not saying zero day... but it was actively exploited before they knew about it - it's a zero day. https://www.bleepingcomputer.com/ ...
  • @gossithedog Kevin Beaumont on x
    Fortinet have gone live with details now. It is indeed a zero day. They're not saying zero day... but it was actively exploited before they knew about it - it's a zero day. https://www.bleepingcomputer.com/ ...