Inside the FortiGate Breach: CVE-2025-59718 Let Attackers Ghost In
Attackers cracked a FortiGate firewall via CVE-2025-59718, bypassed SSO, and prowled silently inside. Responders caught them mid-lateral move—here's the raw playbook.
CVE WatchApr 11, 20263 min read
⚡ Key Takeaways
Attackers used CVE-2025-59718 for stealthy SSO bypass on FortiGate, mimicking admins perfectly.𝕏
IR timeline reconstruction via 'inside-out' from alerts revealed the edge device as entry.𝕏
Hunt anomalous DHCP IPs and Mimikatz for detection; patch and log deeply to prevent.𝕏
The 60-Second TL;DR
Attackers used CVE-2025-59718 for stealthy SSO bypass on FortiGate, mimicking admins perfectly.
IR timeline reconstruction via 'inside-out' from alerts revealed the edge device as entry.
Hunt anomalous DHCP IPs and Mimikatz for detection; patch and log deeply to prevent.