tloh retweetledi

After initial compromise, adversaries are dumping device configs which contain sensitive information, including hashed credentials that could be cracked.
Dray Agha@Purp1eW0lf
For the latest Fortigate CVEs (CVE-2025-59718 & CVE-2025-59719), @HuntressLabs SIEM' is observing the following IPv4s associated with exploitation 📍 38.54.95[.]226 45.32.153[.]218 45.61.136[.]7 167.179.76[.]111 199.247.7[.]82 Detect for .... 🧵
English
























