Fortinet confirmed a new zero-day vulnerability affecting all SAML SSO implementations, including FortiCloud SSO, that allows attackers to bypass authentication and make malicious configuration changes. The attacks, observed since mid-January, differ from a December campaign that exploited two previously patched vulnerabilities. Attackers are extracting firewall configurations, creating unauthorized admin accounts, and granting VPN access. Fortinet is working on a patch while recommending organizations disable FortiCloud SSO, restrict administrative access from the internet, update to the latest software, restore clean backups if compromised, and rotate all credentials.
1 Impression