
AI Powered Attacks Are Hitting Firewalls
AI powered attacks are no longer theoretical. This week, Amazon's security team published findings on a campaign that breached over 600 FortiGate firewalls across 55 countries in just five weeks. The attacker did not use zero-day exploits. They used brute-force attacks against exposed management interfaces, weak credentials without MFA, and AI-generated tooling to automate reconnaissance at scale. If you manage firewalls, VPNs, or any internet-facing infrastructure, this is a wake-up call worth paying attention to. What Actually Happened Between January and February 2026, a Russian-speaking threat actor targeted FortiGate management interfaces exposed to the internet. They scanned for services running on ports 443, 8443, 10443, and 4443 - all common management ports that should never be publicly accessible without strict controls. The attack was opportunistic. No specific industries were targeted. The actor simply looked for weak points and found hundreds of them. Once inside a device,
Continue reading on Dev.to
Opens in a new tab

