Ncerio News blogCVE feed
What we measure across the estates we audit

FortiGate policy audit: 380 open findings across seven targets

A continuous audit of seven FortiGate targets found 295 high-severity policy gaps, the most common being permit rules that allow service "'"ALL'.
10 August 2026

Hackers have crossed from IT to OT networks through a private APN in Poland, according to Security Affairs. The publication reports that attackers breached a Polish combined heat and power plant by exploiting a Fortinet device. This incident has prompted warnings from Poland’s CERT regarding the energy sector's vulnerability to lateral movement.

The mechanism of the breach highlights how standard network designs can be exploited. Attackers accessed Programmable Logic Controllers (PLCs), which allowed them to disrupt critical industrial processes. Specifically, the intrusion affected turbine operations and water treatment systems within the facility. The scope of this attack demonstrates that ordinary-looking connectivity paths can serve as routes into operational technology environments when proper segmentation is missing.

While this incident draws attention to the risks of converged networks, the data presented here comes from a separate, continuous configuration audit. This measurement does not reflect an investigation into the Poland incident but rather a standard review of network hygiene across a specific estate. The audit focused on seven FortiGate targets to identify policy gaps that could facilitate similar lateral movement in any environment.

The assessment identified 380 open findings in total, distributed across medium, high, and low severity levels. A significant portion of these issues stems from overly permissive traffic rules. Among the top gaps is rule FG-POL-002, which requires that permit policies do not allow the service 'ALL'. The audit found 136 instances where this broad allowance was present, creating potential for unrestricted data flow between segments.

Another critical gap involves source and destination addressing. Rule FG-POL-001 dictates that permit policies should not use source 'all' or destination 'all' toward internal networks. This misconfiguration allows traffic from any origin to reach any internal endpoint. The audit counted 67 findings against this rule, indicating a widespread reliance on blanket access rules rather than specific application allowances.

The third major gap relates to security profiles on internet-facing devices. Rule FG-POL-004 mandates that allow policies for internet-facing traffic must have Antivirus, webfilter, and IPS profiles attached. Without these controls, malicious payloads can pass directly into the network. The audit found 53 violations of this rule, leaving a significant number of entry points without essential inspection layers.

This data shows the state of configuration hygiene in the audited estate but cannot be linked to the Poland incident. There is no evidence that the audited FortiGate devices are compromised or involved in the attack reported by Security Affairs. The audit measures routine policy drift, not real-time threat activity or specific breach indicators associated with recent geopolitical events.

To address these gaps, focus on the 136 findings related to service 'ALL'. Review each permit policy to ensure it specifies only the required protocols and ports for that specific segment. Narrowing the scope of allowed services is the most direct way to reduce the attack surface for lateral movement across your own network.

Source: Hackers Cross From IT to OT Through a Private APN in Poland — Security Affairs
← all posts  ·  CVE feed