A newly disclosed critical vulnerability in FortiOS, tracked as CVE-2025-25249, is now being actively exploited in the wild, according to security researchers tracking attacks against FortiGate appliances this week. The flaw, a heap overflow, has reportedly been used to compromise at least 178 devices so far, with attackers deploying a custom piece of malware known as PivotC2 to harvest device configurations and decrypt stored VPN credentials. Early reporting suggests the campaign has focused on organisations in the United States, but history shows that once an exploit for a widely deployed platform like FortiGate becomes public, attackers move quickly to target any exposed device they can find, regardless of geography.
This disclosure did not happen in isolation. The same week, a researcher operating under the name Nightmare Eclipse published working proof of concept exploits against CrowdStrike's Falcon Sensor and, shortly before that, against Kaspersky's endpoint protection. Microsoft's September Patch Tuesday addressed nearly a thousand vulnerabilities across its product line, including two zero days already under active exploitation. Taken together, it has been one of the busiest and most urgent weeks of the year for enterprise security teams, and a clear reminder that no vendor, however well regarded, is immune to this kind of pressure.
For organisations across Kenya and the wider East African region running FortiGate appliances, whether in government, financial services, healthcare or education, the immediate priority is straightforward. Confirm the firmware version running on every FortiGate device in your environment and apply Fortinet's latest patches without delay. Review VPN credential hygiene, since stolen credentials are precisely what this campaign is designed to extract, and consider rotating keys and passwords for any device that has not yet been updated. Where possible, limit management interface exposure to the internet and tighten access controls around remote VPN access points, which remain one of the most common entry routes for this type of attack.
Beyond the immediate patch cycle, this week's news is a useful prompt to revisit broader security posture. Many enterprises in the region still rely on security configurations set up years ago and rarely revisited since. A proper configuration review, paired with credential rotation and monitoring of VPN logs for unusual activity, goes a long way toward reducing exposure not just to this specific vulnerability but to the broader pattern of attacks targeting perimeter security devices.
As a certified partner across several major security vendors, including Fortinet, CrowdStrike, Kaspersky, Bitdefender, Symantec and Mimecast, Intellinks East Africa works with clients across the region to assess exposure, apply patches promptly and strengthen the policies and monitoring that keep these kinds of attacks from turning into full breaches. If your organisation has not reviewed its FortiGate environment or broader perimeter security in the past few months, now is a sensible time to do so.