Hello
Recently there was a post from Fortinet PSIRT about the symlink trick:
https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity
Is there any chance to get information how to find indicators of compromise (IOC)?
I mean I can update to 7.2.11 (I am currently on 7.2.10) but the used CVE's are older and I updated the fortigate before the publication of these CVE's, so there is a small chance to be compromised.
I just want to check if the fortigate is compromised, if yes, i will reinstall it. If no, I just update to 7.2.11 and have a happy life :)
Any ideas?
Solved! Go to Solution.
Hi,
I think the best option here is to contact the official Fortinet support via ticket.
They can also identify exactly which devices are affected and how to check for IoCs (if possible).
KR Fabian
Hi,
I think the best option here is to contact the official Fortinet support via ticket.
They can also identify exactly which devices are affected and how to check for IoCs (if possible).
KR Fabian
Hi Fabian,
Yes, done via Ticket. They sadly don't give more information at the moment how to check for IoCs.
BR
Steve
Great proactive approach! Hopefully, it's all clear after checking!
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.