Christoffer S.<p>ReliaQuest (ex. Digital Shadows): <a href="https://www.reliaquest.com/blog/credential-theft-vs-admin-control-threat-spotlight/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">reliaquest.com/blog/credential</span><span class="invisible">-theft-vs-admin-control-threat-spotlight/</span></a></p><p>This report examines how VPN vulnerabilities, particularly CVE-2018-13379 and CVE-2022-40684 affecting Fortinet products, remain highly exploited years after disclosure. The analysis reveals a 4,223% increase in cybercriminal forum discussions about Fortinet VPNs since 2018, highlighting their continued relevance in attack campaigns. Threat actors exploit these vulnerabilities primarily through credential theft and gaining administrative control. The report details how cybercriminals and state-sponsored APT groups leverage these vulnerabilities, with 64% of VPN vulnerabilities directly linked to ransomware campaigns. The report also examines a 2025 breach by 'Belsen_Group' that compromised over 15,000 FortiGate devices using CVE-2022-40684. The authors provide detection rules, threat hunting recommendations, and defensive strategies to mitigate these threats, while predicting increased hybrid threats targeting VPN infrastructure and the growing impact of AI on VPN exploitation.</p><p><a href="https://swecyb.com/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://swecyb.com/tags/FortinetNot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FortinetNot</span></a> <a href="https://swecyb.com/tags/Fortinet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fortinet</span></a> <a href="https://swecyb.com/tags/Fortigate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fortigate</span></a> <a href="https://swecyb.com/tags/VPN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VPN</span></a> <a href="https://swecyb.com/tags/Vulnerabilities" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vulnerabilities</span></a> <a href="https://swecyb.com/tags/CVE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CVE</span></a> <a href="https://swecyb.com/tags/BelsenGroup" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BelsenGroup</span></a></p>