BEGIN:VCALENDAR
VERSION:2.0
X-WR-CALNAME:BrightTALK Event
PRODID:-//BrightTALK//NONSGML BrightTALK Event Calendar//EN
CALSCALE:GREGORIAN
METHOD:REQUEST
BEGIN:VEVENT
UID:https://www.rapid7.com/about/events-webcasts/brighttalk?commid=671
 245
DTSTAMP:20260807T190725Z
ORGANIZER:MAILTO:no-reply@em.brighttalk.com
LOCATION:BrightTALK
URL:https://www.rapid7.com/about/events-webcasts/brighttalk?commid=671
 245&utm_campaign=communication_reminder_24hr_registrants&utm_medium=ca
 lendar&utm_source=brighttalk-transact
DTSTART:20260812T110000Z
DTEND:20260812T111930Z
SUMMARY:Live webcast: [EMEA] Real-World IR:  Uncovering FortiGate Atta
 ck CVE-2025-59718
DESCRIPTION:Click here to attend: https://www.rapid7.com/about/events-
 webcasts/brighttalk?commid=671245&utm_campaign=communication_reminder_
 24hr_registrants&utm_medium=calendar&utm_source=brighttalk-transact\n\
 nPresenter: Eric Carey, Incident Responder, Rapid7 | Jose Romero, Dete
 ction & Response Analyst, Rapid7\n\nNetwork edge devices like firewall
 s and VPN appliances are prime targets for initial access, yet they re
 main some of the least visible assets in modern IT environments. When 
 attackers gain access to these systems, the most important clues are o
 ften hidden within routine administrative activity, making effective i
 nvestigation and threat hunting especially challenging. \n\nJoin Rapid
 7 incident response experts as they break down a retroactive threat hu
 nt involving FortiGate CVE-2025-59718. Drawing from real-world IR find
 ings, we'll explore how investigators reconstructed attacker activity,
  identified subtle indicators of persistence and connected seemingly b
 enign events to uncover the broader scope of the attack. This session 
 moves beyond exploit mechanics to focus on the investigative mindset, 
 methodologies, and detection opportunities that matter most when audit
 ing edge device compromises.\n\nWhy you should watch:\n– Identify the 
 specific Indicators of Compromise (IOCs) and log patterns associated w
 ith CVE-2025-59718 exploitation\n– Understand why configuration export
 s and rogue account creations are critical flags for perimeter persist
 ence\n– See how proactive, retroactive threat hunts can catch sophisti
 cated attackers before they impact internal operations
SEQUENCE:1786445167
END:VEVENT
END:VCALENDAR
