Before the Alarm: Building an Incident Response Plan That Works
March 31, 2025Agentic AI Is Coming to Your Environment. Is It Governed?
April 22, 2025In April 2025, Fortinet warned that attackers who had exploited older FortiOS SSL-VPN vulnerabilities were maintaining read-only access to affected devices through a symbolic link, even after the original flaws were patched. It is a stark illustration of a lesson defenders keep relearning: patching a vulnerability does not undo a compromise that already happened.
The persistence trap
The technique was clever in its simplicity. By placing a symlink in a location that survived updates, attackers retained visibility into device files, potentially including configurations and credentials, long after the entry vulnerability was closed. Organizations that patched and considered the matter resolved may have remained exposed for months.
Why this keeps happening
- Patching is treated as the finish line rather than one step in remediation.
- Edge devices lack the monitoring we apply to servers and endpoints, so persistence goes unnoticed.
- Old, unpatched exposure creates debt that attackers collect on later.
What to do
If you run Fortinet SSL-VPN, or any appliance that has carried known-exploited vulnerabilities, assume the possibility of prior compromise rather than hoping a patch closed the door. Follow the vendor’s guidance to detect and remove the specific persistence. Rotate every credential the device could have exposed. Where integrity cannot be confirmed, rebuild from clean firmware. Improve monitoring of edge devices going forward.
Takeaway
Patching closes the door but does not evict an intruder who is already inside. For any appliance exposed during a known exploitation window, hunt for persistence, rotate every secret it touched, rebuild when in doubt, and start treating edge devices as monitored assets rather than black boxes.
