FBI warns FortiBleed attacks still target Fortinet firewalls
The FBI and Secret Service have issued a warning that FortiBleed, a campaign exploiting credentials to target Fortinet firewalls and VPN gateways, is ongoing and can lock administrators out of affected devices. Attackers use leaked or stolen credentials to access internet-facing Fortinet devices, create or delete admin accounts, and, in some cases, provide access for ransomware groups. Over 86,000 devices have been compromised globally.
- Attackers use stolen credentials to control Fortinet devices
- Over 86,000 devices confirmed compromised worldwide
- Ransomware groups INC/Lynx and Payload benefit from access
- Standard fixes may not restore admin access to affected systems
- FBI and Secret Service advise multiple defensive steps
Sources covering this
How it unfolded
- CyberScoop Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
- The Register FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
- The Hacker News FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
- BleepingComputer FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
- SecurityWeek FortiBleed Attackers Locking Victims Out of Fortinet Devices
- Infosecurity Magazine FBI and Secret Service Warn of FortiBleed Lockout Threat
More in Cybersecurity
US and allies disrupt Chinese hacking tools targeting infrastructure
US authorities and international partners have seized domains and tools used by China's Integrity Technology Group to support…
AI-powered attacks target South Korean banks
A cyberattack campaign targeting South Korean financial institutions used AI-based tools to steal personal data, CrowdStrike reported.
Google promotes passkeys as a password alternative
Google is highlighting passkeys as a faster and safer alternative to traditional passwords for its accounts.
Malware found pre-installed on low-cost Android phones
Researchers have discovered malware embedded in the firmware of inexpensive Android smartphones, allowing attackers to remotely install…