FortiGate Firewalls Compromised: Why Patching Didn’t Fix the Problem episode artwork

EPISODE · Jun 19, 2026 · 7 MIN

FortiGate Firewalls Compromised: Why Patching Didn’t Fix the Problem

from IT SPARC Cast

Thousands of Fortinet FortiGate devices have been compromised—even in organizations that already applied security patches. In this episode of IT SPARC Cast – CVE of the Week, John and Lou explain how attackers maintained persistence after earlier breaches, why patching alone wasn’t enough, and what every organization running FortiGate firewalls must do immediately to verify they haven’t already been compromised.⸻📄 Show Notes🚨 CVE of the Week (Special Security Alert): FortiGate CompromisesThis week we’re covering a major Fortinet security incident affecting organizations around the world.Unlike most episodes, this isn’t focused on a single CVE. Instead, attackers are leveraging previously exploited FortiGate vulnerabilities and maintaining persistent access even after organizations patched the original flaws.The key lesson:👉 Patching does not remove an attacker who is already inside.⸻⚠️ What Happened?Large organizations across multiple industries have reported compromises involving FortiGate firewalls and VPN infrastructure.Attackers reportedly:Exploited previously disclosed Fortinet vulnerabilitiesEstablished persistence mechanismsMaintained access after patches were installedContinued accessing networks through compromised devicesPotential impacts include:Network visibilityCredential theftTraffic interceptionLong-term unauthorized access⸻🛠️ Immediate Mitigation Steps✅ Audit All FortiGate DevicesIf your FortiGate was internet-facing before patching:Assume compromise until proven otherwise.Review:Administrative accountsVPN configurationsFirewall rulesConfiguration changesScheduled tasks and scripts⸻✅ Upgrade Firmware and SoftwareInstall:Latest supported FortiOS versionLatest firmware updatesAny recommended security updatesDon’t stop at operating system updates—verify firmware integrity as well.⸻✅ Rotate CredentialsImmediately rotate:Administrative passwordsVPN credentialsService accountsShared secretsAPI keysAssume previously exposed credentials may be compromised.⸻✅ Verify Multi-Factor Authentication (MFA)MFA should be enabled for:Firewall administrationVPN accessRemote administrationCritical infrastructure systemsIf MFA is not enabled, prioritize it immediately.⸻✅ Hunt for PersistenceLook for:Unknown accountsSuspicious scriptsUnexpected configuration changesUnauthorized VPN usersUnrecognized scheduled tasksIf something looks unfamiliar, investigate it.⸻🔒 Why This MattersOne of the biggest takeaways from this incident is that perimeter security is no longer enough.If a firewall compromise can expose the entire organization, the network architecture needs work.John and Lou emphasize:Zero Trust architecturesNetwork segmentationLeast privilege accessMFA everywhereContinuous security auditingA firewall should be your first line of defense—not your only line of defense.⸻💡 Key TakeawayThe real danger isn’t the original vulnerability.It’s the persistence left behind after the vulnerability was patched.Organizations that only patch—but don’t investigate for compromise—may still have attackers inside their environments.⸻📣 Wrap UpHave you audited your firewall infrastructure recently? Are you confident patching alone is enough?📧 [email protected]🐦 @itsparccast on X⸻🔗 Social LinksIT SPARC Cast@ITSPARCCast on Xhttps://www.linkedin.com/company/sparc-sales/ on LinkedInJohn Barger@john_Video on Xhttps://www.linkedin.com/in/johnbarger/ on LinkedInLou Schmidt@loudoggeek on Xhttps://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn Hosted on Acast. See acast.com/privacy for more information.

Thousands of Fortinet FortiGate devices have been compromised—even in organizations that already applied security patches. In this episode of IT SPARC Cast – CVE of the Week, John and Lou explain how attackers maintained persistence after earlier breaches, why patching alone wasn’t enough, and what every organization running FortiGate firewalls must do immediately to verify they haven’t already been compromised.⸻📄 Show Notes🚨 CVE of the Week (Special Security Alert): FortiGate CompromisesThis week we’re covering a major Fortinet security incident affecting organizations around the world.Unlike most episodes, this isn’t focused on a single CVE. Instead, attackers are leveraging previously exploited FortiGate vulnerabilities and maintaining persistent access even after organizations patched the original flaws.The key lesson:👉 Patching does not remove an attacker who is already inside.⸻⚠️ What Happened?Large organizations across multiple industries have reported compromises involving FortiGate firewalls and VPN infrastructure.Attackers reportedly:Exploited previously disclosed Fortinet vulnerabilitiesEstablished persistence mechanismsMaintained access after patches were installedContinued accessing networks through compromised devicesPotential impacts include:Network visibilityCredential theftTraffic interceptionLong-term unauthorized access⸻🛠️ Immediate Mitigation Steps✅ Audit All FortiGate DevicesIf your FortiGate was internet-facing before patching:Assume compromise until proven otherwise.Review:Administrative accountsVPN configurationsFirewall rulesConfiguration changesScheduled tasks and scripts⸻✅ Upgrade Firmware and SoftwareInstall:Latest supported FortiOS versionLatest firmware updatesAny recommended security updatesDon’t stop at operating system updates—verify firmware integrity as well.⸻✅ Rotate CredentialsImmediately rotate:Administrative passwordsVPN credentialsService accountsShared secretsAPI keysAssume previously exposed credentials may be compromised.⸻✅ Verify Multi-Factor Authentication (MFA)MFA should be enabled for:Firewall administrationVPN accessRemote administrationCritical infrastructure systemsIf MFA is not enabled, prioritize it immediately.⸻✅ Hunt for PersistenceLook for:Unknown accountsSuspicious scriptsUnexpected configuration changesUnauthorized VPN usersUnrecognized scheduled tasksIf something looks unfamiliar, investigate it.⸻🔒 Why This MattersOne of the biggest takeaways from this incident is that perimeter security is no longer enough.If a firewall compromise can expose the entire organization, the network architecture needs work.John and Lou emphasize:Zero Trust architecturesNetwork segmentationLeast privilege accessMFA everywhereContinuous security auditingA firewall should be your first line of defense—not your only line of defense.⸻💡 Key TakeawayThe real danger isn’t the original vulnerability.It’s the persistence left behind after the vulnerability was patched.Organizations that only patch—but don’t investigate for compromise—may still have attackers inside their environments.⸻📣 Wrap UpHave you audited your firewall infrastructure recently? Are you confident patching alone is enough?📧 [email protected]🐦 @itsparccast on X⸻🔗 Social LinksIT SPARC Cast@ITSPARCCast on Xhttps://www.linkedin.com/company/sparc-sales/ on LinkedInJohn Barger@john_Video on Xhttps://www.linkedin.com/in/johnbarger/ on LinkedInLou Schmidt@loudoggeek on Xhttps://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn Hosted on Acast. See acast.com/privacy for more information.

NOW PLAYING

FortiGate Firewalls Compromised: Why Patching Didn’t Fix the Problem

0:00 7:28

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Breaking News Show | eTurboNews Juergen Thomas Steinmetz News is relevant to the global travel and tourism industry, human rights and global issues.Breaking news when it happens and only from the source. LIGHTS, CAMERA, SMILE! Creatives Club Media Lights, Camera, Smile, is a podcast for anyone with a dream to share something with the world, out of the overflow of themselves - be it their mind, their heart, their personalities, and much more. Each of us are alive in this moment in time, with an innate ability to have ideas and create various things to benefit both ourselves and the people around us for a reason, and here, you will find the encouragement, the inspiration, and the motivation to do just that. Hosted by Cicily, founder of Creatives Club, she dives into various topics surrounding creativity and business. Exploring entrepreneurship for creatives in a corporate reality, sharing tips and tricks in a media centered company, answering questions regarding what a creative actually is are just a few of the things discussed on this podcast. Be encouraged to create for yourself as Cicily gets vulnerable by pivoting the camera to herself for the first time.To submit questions for Cicily to answer, or have her address certain t Invictus by Greyana, A Tomione Podfic M+G Readings Sporadic uploads thanks to gallstones.Voldemort intended the object to be used by his most loyal follower in the event that his horcruxes were destroyed, but it ended up in Hermione’s possession instead.It sent her back to a time when he was much less the monster that she’d always known him to be. Nothing could have prepared her for the intelligence and charm of Tom Riddle.He isn’t who she thought he was.Hermione discovers that it’s a dark descent into the madness of the man she should hate, but can’t… a descent she will never emerge fr The Course Mentors Podcast The Course Mentors Hey there, future course creator!Ever feel like turning your know-how into an online course is like trying to solve a Rubik's cube blindfolded? Well, grab your headphones because "The Course Mentors Podcast" is here to be your secret weapon!Meet Aimee and Odette (that's us!), your new best friends in the course creation world. We've been in the trenches for over a decade, and for the last five years, we've been rocking the online course space. Now we're here to spill all our secrets in bite-sized, 15-20 minute episodes that'll fit perfectly in your coffee breaks.No fluff, no filler - just real, actionable advice that'll take you from "um, what's a landing page?" to "holy moly, I just hit six figures!". We're talking everything from crafting your course to marketing it like a pro and building a business that'll have you pinching yourself.Whether you're dreaming of ditching the 9-to-5 grind, adding a sweet extra income str

Frequently Asked Questions

How long is this episode of IT SPARC Cast?

This episode is 7 minutes long.

When was this IT SPARC Cast episode published?

This episode was published on June 19, 2026.

What is this episode about?

Thousands of Fortinet FortiGate devices have been compromised—even in organizations that already applied security patches. In this episode of IT SPARC Cast – CVE of the Week, John and Lou explain how attackers maintained persistence after earlier...

Can I download this IT SPARC Cast episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!