logo

FortiBleed – Fortinet Warns of Active Credential Harvesting Campaign Targeting FortiGate Devices

ID: 62a1d264-5995-5357-a850-262021e21cc8

STIX ID: report--62a1d264-5995-5357-a850-262021e21cc8

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Guru Baran

...
...

Fortinet warns of an active global credential-harvesting campaign called “FortiBleed” affecting up to 86,000 internet-facing FortiGate devices; actors are reusing previously exposed credentials and using AI-accelerated brute-force attacks against systems lacking strong passwords and MFA, leading to unauthorized configuration changes, creation of rogue admin/VPN accounts, and potential lateral movement into AD/LDAP environments. Fortinet and CISA urge immediate actions: terminate sessions, reset credentials, enforce MFA, upgrade FortiOS to PBKDF2-supporting versions, audit configurations, review logs, and restrict management access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.