HIGH: Fortinet Warns of Persistent Access Technique That Survives Even After Patching
Fortinet has disclosed that threat actors are using a symlink-based technique to maintain read-only access to FortiGate devices even after security patches are applied. The method exploits the SSL-VPN language files directory to create persistent filesystem access.