The attackers exploited a symbolic link (symlink) persistence technique that allows attackers to retain access even after organizations patched the original vulnerabilities.
The attack, first detected by the Shadowserver Foundation, has rapidly escalated, with the number of affected devices rising from 14,000 to more than 17,000 in just days, and is expected to grow as investigations continue.
Authorities and security experts warn that patching alone is insufficient for remediation. Organizations are strongly advised to:
This incident underscores a troubling trend: attackers are exploiting known vulnerabilities rapidly and embedding persistence mechanisms that can survive standard security updates and remediation efforts.
The ability to maintain access after patching poses a significant long-term risk, especially for organizations managing critical infrastructure.
| Aspect | Details |
|---|---|
| Devices Compromised | 17,000+ and rising |
| Main Regions Affected | Asia (most), Europe, North America |
| Attack Technique | Symlink in SSL-VPN language files folder for persistence |
| Vulnerabilities Used | CVE-2022-42475, CVE-2023-27997, CVE-2024-21762 |
| Data at Risk | Configurations, credentials, cryptographic keys |
| Fortinet Response | Firmware updates, AV/IPS signatures, direct customer notifications |
| Security Recommendations | Isolate devices, forensic investigation, reset all credentials/secrets |
| Devices Not Affected | Those without SSL-VPN enabled |
Organizations are urged to remain vigilant, ensure all devices are fully patched, and proactively review system configurations for signs of unauthorized changes or lingering persistence mechanisms.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates
The post Massive Hack Hits 17,000+ Fortinet Devices Through Symlink Vulnerability appeared first on Cyber Security News.
Microsoft says a cybercriminal group it tracks as Storm-2561 is running a credential theft campaign…
Microsoft has announced a two-phase plan to disable the hands-free deployment feature in Windows Deployment…
Full spoilers follow for Primal Season 3, Episode 10, “An Echo of Eternity,” which is…
The year is 2033, and a devastating virus and rogue AI have combined to bring…
The year is 2033, and a devastating virus and rogue AI have combined to bring…
The Oscars just had their seventh tie in the history of the Academy Awards, for…
This website uses cookies.