Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Your Printer Might Stop Working in Windows Soon

    A Complete Guide to iPhone Weather Icons

    What’s the Easiest Way to Stop Webcam Spying? Quick Tips That Work

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      Bernstein Discusses Bitcoin’s Weakest Bear Market Yet – “Nothing Broke”

      February 9, 2026

      Ethereum Price Hits Breakdown Target — But Is a Bigger Drop to $1,000 Coming?

      February 9, 2026

      Damex Secures MiCA CASP Licence, Establishing Its Position as a Tier-1 Digital Asset Institution in Europe

      February 9, 2026

      Bitget and BlockSec Introduce the UEX Security Standard, Setting a New Benchmark for Universal Exchanges

      February 9, 2026

      3 Meme Coins To Watch In The Second Week Of February 2026

      February 9, 2026
    • Technology

      Your Printer Might Stop Working in Windows Soon

      February 10, 2026

      A Complete Guide to iPhone Weather Icons

      February 10, 2026

      What’s the Easiest Way to Stop Webcam Spying? Quick Tips That Work

      February 10, 2026

      All the Places Hidden Apps Show Up on Android

      February 10, 2026

      The Easier Way to Use Network Drives on Mac

      February 10, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Over 25,000 FortiCloud SSO devices exposed to remote attacks
    Technology

    Over 25,000 FortiCloud SSO devices exposed to remote attacks

    TechAiVerseBy TechAiVerseDecember 20, 2025No Comments3 Mins Read1 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Over 25,000 FortiCloud SSO devices exposed to remote attacks
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Over 25,000 FortiCloud SSO devices exposed to remote attacks

    Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability.

    Fortinet noted on December 9th, when it patched the security flaw tracked as CVE-2025-59718 (FortiOS, FortiProxy, FortiSwitchManager) and CVE-2025-59719 (FortiWeb), that the vulnerable FortiCloud SSO login feature is not enabled until admins register the device with the company’s FortiCare support service.

    As cybersecurity company Arctic Wolf reported on Monday, the vulnerability is now actively exploited to compromise admin accounts via malicious single sign-on (SSO) logins.

    Threat actors are abusing it in vulnerable products via a maliciously crafted SAML message to gain admin-level access to the web management interface and download system configuration files. These sensitive files expose potentially vulnerable interfaces, hashed passwords that attackers may crack, internet-facing services, network layouts, and firewall policies.

    Today, Shadowserver said it’s tracking over 25,000 IP addresses with a FortiCloud SSO fingerprint, more than 5,400 in the United States and nearly 2,000 in India.

    However, there is currently no information regarding how many have been secured against attacks exploiting the CVE-2025-59718/CVE-2025-59719 vulnerability.

    Fortinet SSO devices exposed online (Shadowserver)

    ​Macnica threat researcher Yutaka Sejiyama also told BleepingComputer that his scans returned over 30,000 Fortinet devices with FortiCloud SSO enabled, which also expose vulnerable web management interfaces to the internet.

    “Given how frequently FortiOS admin GUI vulnerabilities have been exploited in the past, it is surprising that this many admin interfaces remain publicly accessible,” Sejiyama said.

    On Tuesday, CISA added the FortiCloud SSO auth bypass flaw to its catalog of actively exploited vulnerabilities, ordering U.S. government agencies to patch within a week, by December 23rd, as mandated by the Binding Operational Directive 22-01.

    Fortinet security flaws are frequently exploited by cyber-espionage, cybercrime, or ransomware groups, often as zero-day vulnerabilities.

    For instance, in February, Fortinet disclosed that the notorious Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws (CVE-2023-27997 and CVE-2022-42475) to backdoor a Dutch Ministry of Defence military network using custom Coathanger remote access trojan (RAT) malware.

    More recently, in November, Fortinet warned of a FortiWeb zero-day (CVE-2025-58034) being exploited in the wild, one week after confirming that it had silently patched another FortiWeb zero-day (CVE-2025-64446) that was abused in widespread attacks.


    Break down IAM silos like Bitpanda, KnowBe4, and PathAI

    Broken IAM isn’t just an IT problem – the impact ripples across your whole business.

    This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what “good” IAM looks like, and a simple checklist for building a scalable strategy.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleEx-Splunk execs’ startup Resolve AI hits $1 billion valuation with Series A
    Next Article New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Your Printer Might Stop Working in Windows Soon

    February 10, 2026

    A Complete Guide to iPhone Weather Icons

    February 10, 2026

    What’s the Easiest Way to Stop Webcam Spying? Quick Tips That Work

    February 10, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025661 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025250 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025149 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Technology February 10, 2026

    Your Printer Might Stop Working in Windows Soon

    Your Printer Might Stop Working in Windows Soon If you are a reader experiencing an…

    A Complete Guide to iPhone Weather Icons

    What’s the Easiest Way to Stop Webcam Spying? Quick Tips That Work

    All the Places Hidden Apps Show Up on Android

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Your Printer Might Stop Working in Windows Soon

    February 10, 20262 Views

    A Complete Guide to iPhone Weather Icons

    February 10, 20264 Views

    What’s the Easiest Way to Stop Webcam Spying? Quick Tips That Work

    February 10, 20263 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.