Ncerio News blogCVE feed
What we measure across the estates we audit

Ncerio measures FortiGate policy gaps across a four-client estate

Recent network intrusion highlights configuration risks; our latest audit quantifies exposure on the same vendor.
10 August 2026

Security Affairs reported that attackers in Poland moved from IT to OT through a Fortinet device and a private APN. The breach reached PLCs and disrupted operational systems.

We measured open configurations across 4 clients managing 7 FortiGate targets with Ncerio. The estate contained 295 high-severity, 47 medium-severity, and 38 low-severity findings. We recorded 136 findings for FG-POL-002, 67 for FG-POL-001, and 53 for FG-POL-004 across 7 targets.

This data does not indicate exposure to the reported vector. Both cases relate to FortiGate configuration exposure.

Review and remediate open permit policies before external access is provisioned.

Source: Hackers Cross From IT to OT Through a Private APN in Poland — Security Affairs
← all posts  ·  CVE feed