Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager

Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager

Cybersecurity experts warn of a sharp increase in brute-force attacks targeting Fortinet SSL VPN devices, with activity linked to multiple countries. The attacks are focused, evolving, and potentially launching from residential networks or proxies. #Fortinet #SSLVPN #CyberThreats #BruteForceAttacks

Keypoints

  • The attacks involve over 780 IP addresses from multiple countries targeting Fortinet VPNs.
  • Two distinct attack waves were observed, shifting focus from FortiOS to FortiManager systems.
  • Attackers may be using residential networks or proxies to launch brute-force campaigns.
  • Historical data suggests initial testing from residential ISP blocks, indicating sophisticated attack methods.
  • Spike in activity often precedes the release of new CVEs affecting enterprise network devices.

Read More: https://thehackernews.com/2025/08/fortinet-ssl-vpns-hit-by-global-brute.html