LLMs Scout 2516 FortiGate Targets Across 106 Countries

💡First reported LLM-automated cyberattack on firewalls—learn how attackers use Claude for recon
⚡ 30-Second TL;DR
What Changed
Attack hit 2516 targets in 106 countries via FortiGate breaches
Why It Matters
Highlights rising risks of LLMs aiding sophisticated cyberattacks, urging AI practitioners to prioritize model misuse defenses. Enterprises using FortiGate must enhance monitoring for AI-assisted threats.
What To Do Next
Audit FortiGate logs for anomalous LLM-like query patterns immediately.
Key Points
- •Attack hit 2516 targets in 106 countries via FortiGate breaches
- •Claude Code and DeepSeek used for automated reconnaissance and planning
- •LLMs integrated post-intrusion for multi-country simultaneous attacks
🧠 Deep Insight
Background and context from public sources — not the original article. 10 sources cited.
🔑 Enhanced Key Takeaways
- •The threat actor, likely Russian-speaking and financially motivated, originated scans from IP 212.11.64.250 and targeted management ports 443, 8443, 10443, and 4443 without exploiting vulnerabilities[1][3][4].
- •Post-exploitation involved Active Directory attacks like DCSync, pass-the-hash, pass-the-ticket, NTLM relay, and targeting backup systems such as Veeam using known CVEs like CVE-2024-40711[1][4].
- •Custom tools included ARXON MCP server for LLM processing, CHECKER2 Go-based orchestrator for VPN scanning, and prior use of HexStrike AI framework exposed in December 2025[2][3].
🛠️ Technical Deep Dive
- •Attackers used a custom Model Context Protocol (MCP) server named ARXON to process reconnaissance data, invoke DeepSeek for attack plans, and modify victim infrastructure[2][3].
- •CHECKER2, a Go-based orchestrator, enabled parallel VPN scanning and target processing[3].
- •Scripts like deepseek_attack_plan.py cataloged vulnerable systems, including ZKSoftware biometric devices potentially via CVE-2026-24061 telnet bypass[2].
- •Automated network classification by size, routing table analysis, Nuclei vulnerability scanning, SMB/DC identification, and HTTP service discovery[4].
🔮 Future ImplicationsAI analysis grounded in cited sources
⏳ Timeline
📎 Sources (10)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- zeron.one — AI Powered Fortigate Cyberattack 2026
- cyberandramen.net — Llms in the Kill Chain Inside a Custom Mcp Targeting Fortigate Devices Across Continents
- thehackernews.com — AI Assisted Threat Actor Compromises
- computing.co.uk — AI Powered Hacker Breaches 600 Fortigate Firewalls
- ampcuscyber.com — AI Powered Hacker Compromises 600 Fortigate Devices Worldwide
- cybersecuritynews.com — 600 Fortigate Devices Hacked
- sans.org — Xxviii 03
- evlconsulting.com.au — Cyber Incidents Digest 2026 02 22
- cyberpress.org — Deepseek Claude Target Fortigate
- mescomputing.com — AI Powered Ransomware Explodes in 2026 After a Brief 2025 Slowdown
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: ITmedia AI+ (日本) ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
Weekly AI briefing
One email a week. Unsubscribe anytime.