FortiBleed – Fortinet Warns of Active Credential Harvesting Campaign Targeting FortiGate Devices
ID: 62a1d264-5995-5357-a850-262021e21cc8
STIX ID: report--62a1d264-5995-5357-a850-262021e21cc8
Feed Name: cybersecurityNews.com
Fortinet warns of an active global credential-harvesting campaign called “FortiBleed” affecting up to 86,000 internet-facing FortiGate devices; actors are reusing previously exposed credentials and using AI-accelerated brute-force attacks against systems lacking strong passwords and MFA, leading to unauthorized configuration changes, creation of rogue admin/VPN accounts, and potential lateral movement into AD/LDAP environments. Fortinet and CISA urge immediate actions: terminate sessions, reset credentials, enforce MFA, upgrade FortiOS to PBKDF2-supporting versions, audit configurations, review logs, and restrict management access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
