More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Over 86,000 internet-facing Fortinet firewalls and VPNs have had their credentials stolen in a campaign dubbed FortiBleed. SOCRadar first spotted more than 30,000 compromised devices and has since confirmed 86,644 valid username-password pairs from infrastructure in 194 countries. Security researcher Kevin Beaumont and Hudson Rock verified these logins are current, noting they represent about half of all publicly exposed Fortinet firewalls, based on Shodan scans.
Russian-speaking attackers intercepted SSL VPN authentications, then used a 45-GPU Hashtopolis cluster to crack passwords. They’ve logged roughly 1.16 billion credential checks against 320,000 FortiGate devices and launched 2.1 billion brute-force attempts on over 160,000 Microsoft SQL servers. At least four organizations are fully compromised; thousands more—including government agencies and critical infrastructure providers—have seen some level of penetration.
Huntress cross-referenced the leaked IPs with its own data and found 845 partner organizations directly affected. CISA has issued an alert urging immediate hardening steps: terminate active sessions, reset all credentials, switch to PBKDF2 for storing admin passwords, review logs for suspicious access, enable phishing-resistant multi-factor authentication, and restrict management interfaces to known IPs.
Questions about this article
No questions yet.