logo

CISA Warns of Active Exploitation Following FortiBleed Leak

ID: 881910f4-f25c-53f7-b869-ce7d6566230b

STIX ID: report--881910f4-f25c-53f7-b869-ce7d6566230b

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-06-20

Date Updated: 2026-06-20

Author: Pierluigi Paganini

...
...

**FortiBleed — Active exploitation of leaked Fortinet credentials:** CISA issued an emergency alert after researchers discovered plaintext VPN and admin credentials (and device config exports) for ~74k Fortinet devices that attackers are actively using worldwide; evidence includes confirmed working logins, a dataset spanning 194 countries and 21k+ domains, large-scale cracking operations (45‑GPU Hashtopolis), billions of credential attempts, and reported compromises of organizations across multiple countries. Recommended mitigations include immediate session termination and password resets, enabling phishing‑resistant MFA, upgrading FortiOS and forcing admin re-login to rehash credentials, and removing management interfaces from the public internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.