On 9 March 2023 Fortinet released an analysis detailing the initial investigation that led to the discovery of CVE-2022-41328. This is unrelated to the CVE that was announced earlier this month (CVE-2023-25610), but was addressed in the same update cycle which addressed that vulnerability. The investigation indicates that the attacks were targeted towards government organizations. Specifically, the threat actor used the ability to read and write arbitrary files to modify the firmware in order to establish persistence, command and control, and exfiltration activities. The attack was discovered after several FortiGate devices crashed and failed to boot.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security