Get the latest tech news

China state hackers infected 20,000 Fortinet VPNs, Dutch spy service says


Critical code-execution flaw was under exploitation 2 months before company disclosed it.

The Netherlands officials first reported in February that Chinese state hackers had exploited CVE-2022-42475 to install an advanced and stealthy backdoor tracked as CoatHanger on Fortigate appliances inside the Dutch Ministry of Defence. Once installed, the never-before-seen malware, specifically designed for the underlying FortiOS operating system, was able to permanently reside on devices even when rebooted or receiving a firmware update. The Dutch intelligence services and the NCSC consider it likely that the state actor could potentially expand its access to hundreds of victims worldwide and carry out additional actions such as stealing data.

Get the Android app

Or read this on r/technology

Read more on:

Photo of China

China

Photo of Dutch

Dutch

Photo of Dutch spy service

Dutch spy service

Related news:

News photo

US Weighs More Limits on China’s Access to AI Chips

News photo

US Weighs More Limits on China’s Access to Chips Needed for AI

News photo

Huawei exec concerned over China’s inability to obtain 3.5nm level chips, bemoans lack of advanced chipmaking tools