Researchers observed active exploitation using two distinct methods within days after a proof-of-concept exploit was released on Jan. 27, according to the Forescout Research blog post.
In certain cases, the attacks involved exploiting the WebSocket vulnerability through a vulnerability in the jconsole interface.
In other cases, exploitation occurred using direct HTTPS requests. While this method looks different in logs, researchers said the same underlying vulnerability is targeted.
Initial login attempts were made using randomly generated five-character usernames. The threat actor then created local system admin users.
Researchers said the largest number of exposed FortiGate firewalls are in the U.S. with 7,677, followed by India and Brazil.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
