(TLP:CLEAR) WaterISAC Notification – Post-Exploitation Technique Used to Maintain Read-Only Access to Fortinet SSL-VPN
Members using Fortinet FortiGate / FortiOS with SSL-VPN enabled are encouraged to review this notification and address accordingly.
What you need to know: Fortinet warns that threat actors are using a post-exploitation technique that helps them maintain read-only access to previously compromised FortiGate VPN devices even after the original attack vector was patched.