Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware

An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) that turns compromised perimeter devices into long-term footholds for espionage and data theft. The SOCRadar Threat Research Unit (STRU) has identified, with high confidence, that threat actors are actively exploiting CVE-2025-25249, a […]

This article has been indexed from Cyber Security News

Read the original article: