Executive Summary
In early November 2025, a coordinated multi-vector campaign targeted Fortinet infrastructure worldwide, exploiting unpatched vulnerabilities in FortiGate VPN appliances. Attackers—some with ties to Chinese state-affiliated threat groups—combined AI-driven phishing-as-a-service (PhaaS) toolkits, malicious code deployment, and supply chain manipulation to bypass legacy perimeter defenses. The campaign leveraged trusted encrypted channels and cloud infrastructure to evade detection, enabling lateral movement and data exfiltration from government agencies, finance firms, and Fortune 500 companies. Cleanup and containment efforts required full infrastructure reviews and forensic triage, disrupting operations across multiple sectors.
This incident exemplifies the accelerating convergence of advanced attacker automation, trusted-tool abuse (AI, VPNs), and commercial cybercrime platforms. Organizations must urgently address gaps in segmentation, encrypted traffic inspection, and detection controls to withstand increasingly stealthy, multi-stage attacks.
Why This Matters Now
This campaign highlights how attackers are leveraging a blend of automation, AI tools, and supply chain weaknesses to execute complex breaches undetected. As organizations grow more reliant on distributed and encrypted environments, traditional defenses are quickly outpaced—making rapid, adaptive security architectures a critical and urgent business priority.
Attack Path Analysis
Attackers initially compromised the cloud environment by exploiting a vulnerable or misconfigured Fortinet device, gaining a foothold using valid credentials or exposed services. They then escalated privileges through IAM abuse or lateral token theft, increasing access within the environment. Leveraging internal pathways, adversaries moved laterally across east-west traffic, accessing additional workloads and even Kubernetes clusters. They established command and control using encrypted outbound traffic and covert channels to evade detection. Data was exfiltrated via unmonitored egress, possibly through cloud storage or SaaS endpoints. Ultimately, the attackers enacted impact actions such as deploying ransomware or deleting backups, aiming for business disruption or ransom demands.
Kill Chain Progression
Initial Compromise
Description
Exploited Fortinet device vulnerability or cloud misconfiguration allowed initial unauthorized access with valid credentials or a public-facing exploitation.
Related CVEs
CVE-2025-64446
CVSS 9.8A relative path traversal vulnerability in Fortinet's FortiWeb Web Application Firewall allows unauthenticated attackers to execute administrative commands remotely.
Affected Products:
Fortinet FortiWeb – 8.0.0 to 8.0.1, 7.6.0 to 7.6.4, 7.4.0 to 7.4.9, 7.2.0 to 7.2.11, 7.0.0 to 7.0.11
Exploit Status:
exploited in the wildReferences:
https://www.cyber.gc.ca/en/alerts-advisories/al25-017-vulnerability-impacting-fortinet-fortiweb-cve-2025-64446https://cyber.gov.rw/updates/article/alert-active-exploitation-of-critical-fortiweb-vulnerability-november-2025/https://www.techradar.com/pro/security/fortinet-customers-told-to-update-immediately-following-major-security-issue-heres-what-we-knowCVE-2025-58034
CVSS 6.7An OS command injection vulnerability in Fortinet's FortiWeb allows authenticated attackers to execute arbitrary code via crafted HTTP requests or CLI commands.
Affected Products:
Fortinet FortiWeb – 8.0.0 to 8.0.1, 7.6.0 to 7.6.5, 7.4.0 to 7.4.10, 7.2.0 to 7.2.11, 7.0.0 to 7.0.11
Exploit Status:
exploited in the wildReferences:
https://cyber.gov.rw/updates/article/alert-fortiweb-zero-day-cve-2025-58034-actively-exploited-november-2025/https://www.esentire.com/security-advisories/fortinet-fortiweb-zero-day-vulnerability-cve-2025-58034-exploited-in-the-wildhttps://www.cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av25-769
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Phishing
Command and Scripting Interpreter
User Execution
Proxy
Acquire Infrastructure
Data from Local System
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Public-Facing Application Security
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Multi-vector campaigns targeting encrypted traffic and east-west segmentation pose critical risks to financial data protection and regulatory compliance requirements.
Health Care / Life Sciences
Zero trust segmentation vulnerabilities and threat detection gaps expose patient data to lateral movement attacks and HIPAA compliance violations.
Government Administration
Nation-state AI exploitation and encrypted traffic compromise threaten critical infrastructure visibility and secure hybrid connectivity for government operations.
Information Technology/IT
Cloud-native security fabric weaknesses enable shadow AI risks and egress security bypasses, compromising multicloud visibility and Kubernetes protection.
Sources
- ⚡ Weekly Recap: Fortinet Exploited, China's AI Hacks, PhaaS Empire Falls & Morehttps://thehackernews.com/2025/11/weekly-recap-fortinet-exploited-chinas.htmlVerified
- Vulnerability impacting Fortinet FortiWeb – CVE-2025-64446https://www.cyber.gc.ca/en/alerts-advisories/al25-017-vulnerability-impacting-fortinet-fortiweb-cve-2025-64446Verified
- Alert: Active Exploitation of Critical FortiWeb Vulnerability – November 2025https://cyber.gov.rw/updates/article/alert-active-exploitation-of-critical-fortiweb-vulnerability-november-2025/Verified
- Fortinet customers told to update immediately following major security issue - here's what we knowhttps://www.techradar.com/pro/security/fortinet-customers-told-to-update-immediately-following-major-security-issue-heres-what-we-knowVerified
- Alert: FortiWeb Zero-Day CVE-2025-58034 Actively Exploited – November 2025https://cyber.gov.rw/updates/article/alert-fortiweb-zero-day-cve-2025-58034-actively-exploited-november-2025/Verified
- Fortinet FortiWeb Zero-Day Vulnerability (CVE-2025-58034) Exploited in the Wildhttps://www.esentire.com/security-advisories/fortinet-fortiweb-zero-day-vulnerability-cve-2025-58034-exploited-in-the-wildVerified
- Fortinet security advisory (AV25-769)https://www.cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av25-769Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Zero Trust segmentation, east-west visibility, and egress enforcement would have contained the attack early, preventing lateral movement and data exfiltration. CNSF-aligned controls limit attacker reach by enforcing workload isolation, continuous anomaly detection, and encrypted communications, greatly reducing the attack’s blast radius.
Control: Cloud Firewall (ACF)
Mitigation: Blocked unauthorized inbound connections at the cloud perimeter.
Control: Zero Trust Segmentation
Mitigation: Containted access and limited escalation opportunities.
Control: East-West Traffic Security
Mitigation: Detected and blocked unauthorized lateral communications.
Control: Egress Security & Policy Enforcement
Mitigation: Denied or alerted on suspicious outbound connections.
Control: Encrypted Traffic (HPE) & Cloud Native Security Fabric (CNSF)
Mitigation: Prevented unauthorized data transfer and provided audit visibility.
Detected and alerted on destructive actions or anomalous behavior.
Impact at a Glance
Affected Business Functions
- Web Application Security
- Network Security
- Data Protection
Estimated downtime: 3 days
Estimated loss: $500,000
Potential unauthorized access to sensitive data due to administrative control gained by attackers.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce perimeter controls with cloud-native firewalls to block unauthorized inbound access and scan for misconfigurations.
- • Implement zero trust segmentation and least privilege policies for all cloud identities, workloads, and Kubernetes namespaces.
- • Deploy robust east-west traffic inspection to detect and halt lateral movement across internal cloud environments.
- • Apply strict egress filtering and encrypted visibility to control outbound connections and prevent data exfiltration.
- • Continuously monitor for anomalies and respond rapidly to suspicious activities using real-time threat detection tools.



