Hackers Use Claude, DeepSeek to Hit FortiGate VPNs
In February 2026, hackers use Claude and DeepSeek in a sophisticated wave of cyberattacks targeting FortiGate devices worldwide. These advanced AI-powered strategies integrate Large Language Models to automate complex tasks within the intrusion chain. Misconfigured servers revealed that attackers embedded Claude and DeepSeek into their operations, focusing on FortiGate SSL VPN appliances. By exploiting stolen configuration data, the hackers efficiently mapped networks and targeted critical assets.
The attackers employed custom tools, ARXON and CHECKER2, to manage thousands of targets concurrently without manual intervention. This automated workflow, involving Claude’s ability to execute vulnerability assessments, enabled even less experienced operators to conduct widespread intrusions. Cybersecurity analysts uncovered logs showing over 2,500 compromised devices across 106 countries, highlighting the global scale of this threat.
Companies must prioritize patching edge devices promptly to defend against these AI-driven attacks. To explore the full depth of this emerging cyber threat, read more in the detailed analysis provided in the full article.
Hackers Leverage DeepSeek and Claude to Attack FortiGate Devices Worldwide
