FortiBleed Exploit Campaign Hits 70,000+ Fortinet Firewalls Worldwide
ID: cf0d3321-f67d-5a84-8b06-e3259bc2b495
STIX ID: report--cf0d3321-f67d-5a84-8b06-e3259bc2b495
Feed Name: GBHackers
FortiBleed is a widespread exploitation campaign that exposed 73,932 Fortinet devices across 194 countries by extracting configuration files and offline credential hashes, enabling ~1.16 billion credential attempts and subsequent administrative logins, lateral movement, and data exfiltration; victims include major corporations and government entities. The operation is linked to a Russian‑speaking criminal group using automated scanning and a 45‑GPU cracking cluster (Hashtopolis) to rapidly recover passwords, and investigators recommend removing public management access, full credential rotation and rehashing under PBKDF2, MFA enforcement, and forensic response to assume persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
