I was told yesterday by someone I trust that a lot of companies in the accounts receivable management industry have firewalls from a company called FortiGate. If you do not know who your firewall provider is, you may want to take a second and check. A recent warning from the Dutch National Cyber Security Center has revealed that a significant cyberespionage campaign by Chinese state-sponsored hackers has breached thousands of FortiGate network security appliances. This breach is far more extensive than initially reported, affecting numerous Western governments, international organizations, and defense contractors.
More than 20,000 FortiGate devices have been impacted, according to published reports.
If your devices have used any of the following FortiOS versions since September 2022, they may be compromised or at risk:
- FortiOS version 7.2.0 through 7.2.2
- FortiOS version 7.0.0 through 7.0.8
- FortiOS version 6.4.0 through 6.4.10
- FortiOS version 6.2.0 through 6.2.11
- FortiOS-6K7K version 7.0.0 through 7.0.7
- FortiOS-6K7K version 6.4.0 through 6.4.9
- FortiOS-6K7K version 6.2.0 through 6.2.11
- FortiOS-6K7K version 6.0.0 through 6.0.14
The attackers deployed a sophisticated malware strain known as “Coathanger,” which can persist on devices even after reboots and firmware upgrades. This malware is difficult to detect and remove, posing a significant threat to compromised systems. The vulnerability allows attackers to execute arbitrary code or commands on unpatched devices, providing them with a persistent foothold in many networks. This persistence means that rebooting the device or installing firmware upgrades will not remove the malware. The malware carries a severity rating of 9.8 out of 10, which can’t be good.
If it is determined that you have been compromised, the only way to remove the malware from the device is “to completely reformat the device, before reinstalling and reconfiguring it.”
Learn More.




