
Critical FortiGate Flaw Exploited to Deploy PivotC2 RAT and Steal Credentials
Threat actors are actively exploiting CVE-2025-25249, a critical heap-based buffer overflow in FortiOS and FortiSwitchManager’s cw_acd daemon, to compromise exposed FortiGate firewalls and deploy the PivotC2 remote access trojan (RAT). SOCRadar Threat Research Unit (STRU) assessed with high confidence that exploitation began no later than July 2026 and remains active. The campaign reportedly targeted more […]
The post Critical FortiGate Flaw Exploited to Deploy PivotC2 RAT and Steal Credentials appeared first on Cyber Security News.