FortiBleed: 30,791 Fortinet Firewalls Compromised in Global Credential Heist
ID: 3c4204a4-ae40-52df-8fe1-5c090e33ec92
STIX ID: report--3c4204a4-ae40-52df-8fe1-5c090e33ec92
Feed Name: securityonline.info
FortiBleed is an active, large-scale campaign delivering verified admin credentials for Fortinet firewalls and VPN gateways (≈30,791 devices across 194 countries). Attackers automate internet scanning and credential stuffing using reused credentials from prior leaks, convert compromised devices into passive harvesters that feed new credentials back into the scanner, and target critical sectors; SOCRadar rates the campaign Critical and advises immediate password rotation, MFA on admin/VPN accounts, and removal of management interfaces from the public internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
