Zero-Day Mayhem: Fortinet Firewalls Under Siege by Sneaky Attackers!

Fortinet warns of a zero-day bug in FortiOS and FortiProxy allowing attackers to hijack firewalls. This vulnerability, CVE-2025-24472, gives super-admin privileges with crafty CSF proxy requests. Fortinet firewalls are now in the spotlight, and not in a good way. Time to patch up before hackers turn your network into their playground.

Pro Dashboard

Hot Take:

Fortinet’s firewalls have more bypasses than a highway construction zone! Just when you thought you were safe with a zero-day patch, another sneaky vulnerability zooms in to crash the party. It’s like playing whack-a-mole with cyber threats, and the moles are winning.

Key Points:

  • Fortinet firewalls are being hijacked through a newly discovered zero-day vulnerability.
  • The bug, CVE-2025-24472, allows attackers to gain super-admin privileges.
  • Vulnerabilities affect FortiOS and FortiProxy versions, leading to unauthorized access.
  • Arctic Wolf Labs reported widespread attacks on Fortinet devices since November 2024.
  • Admins are advised to disable public management access as a temporary fix.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?