As cited
Copy frozen at (site build).
ransomware
An update on FortiBleed - what’s happening with victim orgs
FortiBleed exposed Fortinet firewall administrator credentials at scale after an attacker gained access to tens of thousands of devices, exported configurations, and cracked password hashes using rented GPU compute resources. The attacker's infrastructure left evidence in an open directory, revealing that approximately 1,000 organizations were directly compromised, though credential theft occurred across tens of thousands of devices, with stolen FortiVPN credentials now being resold on underground forums. Many victim organizations show evidence of configuration exports in their logs over the past month from multiple IP addresses.
Why it matters: Fortinet firewall administrators and security teams managing Fortigate devices need to immediately review System event logs for unauthorized config exports, verify whether their devices were compromised, rotate administrative credentials, and investigate whether dormant backdoor accounts from prior ransomware campaigns are present in their infrastructure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
An update on FortiBleed - what’s happening with victim orgs
FortiBleed exposed Fortinet firewall administrator credentials at scale after an attacker gained access to tens of thousands of devices, exported configurations, and cracked password hashes using rented GPU compute resources. The attacker's infrastructure left evidence in an open directory, revealing that approximately 1,000 organizations were directly compromised, though credential theft occurred across tens of thousands of devices, with stolen FortiVPN credentials now being resold on underground forums. Many victim organizations show evidence of configuration exports in their logs over the past month from multiple IP addresses.
Why it matters: Fortinet firewall administrators and security teams managing Fortigate devices need to immediately review System event logs for unauthorized config exports, verify whether their devices were compromised, rotate administrative credentials, and investigate whether dormant backdoor accounts from prior ransomware campaigns are present in their infrastructure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
An update on FortiBleed - what’s happening with victim orgs
FortiBleed exposed Fortinet firewall administrator credentials at scale after an attacker gained access to tens of thousands of devices, exported configurations, and cracked password hashes using rented GPU compute resources. The attacker's infrastructure left evidence in an open directory, revealing that approximately 1,000 organizations were directly compromised, though credential theft occurred across tens of thousands of devices, with stolen FortiVPN credentials now being resold on underground forums. Many victim organizations show evidence of configuration exports in their logs over the past month from multiple IP addresses.
Why it matters: Fortinet firewall administrators and security teams managing Fortigate devices need to immediately review System event logs for unauthorized config exports, verify whether their devices were compromised, rotate administrative credentials, and investigate whether dormant backdoor accounts from prior ransomware campaigns are present in their infrastructure.
- Source published
- First seen by Cybersecurity Tracker