
Russian group uses AI to exploit weakly-protected Fortinet firewalls, says Amazon
A Russian-speaking threat actor is using commercial generative AI services to compromise hundreds of Fortinet Fortigate firewalls, warns Amazon Threat Intelligence. Once on the network, the hackers successfully compromised Active Directory at hundreds of organizations, extracted complete credential databases, and targeted backup infrastructure — a potential precursor to ransomware deployment, the report adds. The report, by CJ Moses, CISO of Amazon Integrated Security, is another signal that commercial AI services are lowering the technical barrier to entry for offensive cyber capabilities. A single actor, or a very small group, generated its entire toolkit through AI-assisted development, A...