: Investigations suggest the data was likely stolen in late 2022 . The leak is believed to be the result of attackers exploiting a specific authentication bypass vulnerability, CVE-2022-40684 , which allowed administrative access to affected FortiOS, FortiProxy, and FortiSwitchManager products.
The file is linked to a significant cybersecurity incident involving the Belsen Group (or a group using that name) that surfaced around mid-January 2025. Configs Leaked.rar
So the data was probably stolen in the fall of 2022, but where and how did the unknown attackers obtain the sensitive information? heise online : Investigations suggest the data was likely stolen
: The .rar archive reportedly includes sensitive information such as: IP addresses and port details. Firewall configuration settings. Hashed or plain-text VPN passwords. So the data was probably stolen in the
Unknown group releases Fortinet config files and VPN ... - Heise
The leak contains approximately and VPN credentials from Fortinet FortiGate firewalls . Key Details of the Leak
: Ensure your firmware is updated to versions that patch CVE-2022-40684 .
: Investigations suggest the data was likely stolen in late 2022 . The leak is believed to be the result of attackers exploiting a specific authentication bypass vulnerability, CVE-2022-40684 , which allowed administrative access to affected FortiOS, FortiProxy, and FortiSwitchManager products.
The file is linked to a significant cybersecurity incident involving the Belsen Group (or a group using that name) that surfaced around mid-January 2025.
So the data was probably stolen in the fall of 2022, but where and how did the unknown attackers obtain the sensitive information? heise online
: The .rar archive reportedly includes sensitive information such as: IP addresses and port details. Firewall configuration settings. Hashed or plain-text VPN passwords.
Unknown group releases Fortinet config files and VPN ... - Heise
The leak contains approximately and VPN credentials from Fortinet FortiGate firewalls . Key Details of the Leak
: Ensure your firmware is updated to versions that patch CVE-2022-40684 .
The following download link is available for your IP: 185.104.194.44 until 2025-12-14 09:10:11 GMT
https://xdafix.com/index.php?a=downloads&b=file&c=download&id=224&vtoken=224_1765703411_99b4350a873153d2272fd96dae28223b