FBI and Secret Service warn FortiBleed still targets Fortinet devices

First reported by CyberScoop at · Updated · 6 sources

The credential-stealing campaign has compromised 86,644 Fortinet devices across 194 countries, with internet-facing FortiGate firewalls and SSL VPN gateways among its targets. The agencies warned that the threat remains active, and reports describe risks including administrators being locked out of affected systems and potential ransomware attacks.

  • The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, according to The Hacker News.

Covered by 6 publishers within 24 hours of the first report.

Reporting6

The Hacker News FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials · info@thehackernews.com (The Hacker News)
Security Affairs FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away · Pierluigi Paganini
BleepingComputer FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins · Bill Toulas

Related

Topics Ransomware