Thai Broadband Provider Hit by Fortinet Flaw

Thai Broadband's Fortinet FortiGate firewall was compromised by hackers exploiting a CVE-2021-22522 vulnerability, allowing them to execute scripts and probes to gather sensitive information.

Bottom line: The vulnerability's exploitation enabled the hackers to gain unauthorized access to the network.

What's happening: Thai Broadband's FortiGate firewall was targeted by hackers exploiting a CVE-2021-22522 vulnerability, allowing them to execute scripts and probes to gather sensitive information. The attack occurred in June 2022, with Thai Broadband's security team responding within 24 hours. The hackers used brute-force utilities and privilege escalation tools, as well as reconnaissance scripts.

What to do: Security leaders should review and update their Fortinet FortiGate firewalls to apply the CVE-2021-22522 patch, and consider conducting regular vulnerability assessments to prevent similar attacks. Additionally, they should ensure that all system administrators and network engineers undergo regular training on security best practices.

Source: SecurityWeek