Cybersecurity company Arctic Wolf has warned of a “new cluster of automated malicious activity” that involves unauthorized firewall configuration changes on Fortinet FortiGate devices.
The activity, it said, commenced on January 15, 2026, adding it shares similarities with a December 2025 campaign in which malicious SSO logins on FortiGate appliances were recorded against the admin account from –
Read More – The Hacker News



![[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks AttackFeed by Joe Wagner | [Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks - The Hacker News](https://attackfeed.com/wp-content/uploads/2026/03/validate-3lC6Rk.jpg)