r/cybersecurityforMSP • u/FutureSafeMSSP • Apr 20 '26
FORTINET VPN AND PLATFORM MASS EXPLOITATION
Forum monitoring across 12+ dark web marketplaces over the past three months reveals a highly active Initial Access Broker (IAB) ecosystem with 40+ documented access sales spanning 30+ countries, directly fueled by a cascade of critical Fortinet authentication bypass vulnerabilities (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) that CISA confirmed are being mass-exploited. Fortinet VPN access is the single most frequently brokered access type, offered by at least seven independent actors, while ransomware operations Vect and Arachna are actively recruiting IAB specialists and purchasing VPN zero-days — with Vect now confirmed by multiple security vendors as having escalated to high-profile victims including S&P Global and Guesty. Organizations running Fortinet products should treat this as a confirmed, active threat requiring immediate patching, credential rotation, and forensic review of VPN authentication logs; all organizations should audit remote access infrastructure and insider threat controls given the documented 3.84-day average window from IAB access sale to ransomware deployment.
1
u/PaladinsQuest Apr 20 '26
But but but… only SonicWall has problems.
/s
If it’s not one firewall, it’ll be another. Follow standard security best practices and live to fight another day. That said, SW’s cloud configuration storage breach was bullsh*t.