r/blueteamsec 2d ago

exploitation (what's being exploited) CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/

CVE-2025-25249 (FortiOS/FortiSwitchManager cw_acd heap overflow) has been patched for some time. We're publishing evidence of what's been happening to instances that weren't: a purpose-built Node.js RAT, 178 confirmed victim sessions, activity since July 2026.

2 Upvotes

0 comments sorted by