Cybersecurity firm Arctic Wolf has warned of a “new cluster of automated malicious exercise” that entails unauthorized firewall configuration modifications on Fortinet FortiGate gadgets.
The exercise, it mentioned, commenced on January 15, 2026, including it shares similarities with a December 2025 marketing campaign through which malicious SSO logins on FortiGate home equipment have been recorded in opposition to the admin account from completely different internet hosting suppliers by exploiting CVE-2025-59718 and CVE-2025-59719.
Each vulnerabilities permit for unauthenticated bypass of SSO login authentication through crafted SAML messages when the FortiCloud single sign-on (SSO) function is enabled on affected Gadgets. The shortcomings influence FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager.

“This exercise concerned the creation of generic accounts meant for persistence, configuration modifications granting VPN entry to these accounts, in addition to exfiltration of firewall configurations,” Arctic Wolf mentioned of the growing menace cluster.
Particularly, this entails finishing up malicious SSO logins in opposition to a malicious account “cloud-init@mail.io” from 4 completely different IP addresses, following which the firewall configuration recordsdata are exported to the identical IP addresses through the GUI interface. The listing of supply IP addresses is under –
- 104.28.244[.]115
- 104.28.212[.]114
- 217.119.139[.]50
- 37.1.209[.]19
As well as, the menace actors have been noticed creating secondary accounts, akin to “secadmin,” “itadmin,” “help,” “backup,” “remoteadmin,” and “audit,” for persistence.
“The entire above occasions came about inside seconds of one another, indicating the opportunity of automated exercise,” Arctic Wolf added.

The disclosure coincides with a put up on Reddit through which a number of customers reported seeing malicious SSO logins on fully-patched FortiOS gadgets, with one consumer stating the “Fortinet developer group has confirmed the vulnerability persists or shouldn’t be mounted in model 7.4.10.”
The Hacker Information has reached out to Fortinet for remark, and we’ll replace the story if we hear again. Within the interim, it is suggested to disable the “admin-forticloud-sso-login” setting.



