logo

Analysis of Reported Credential Compromise of FortiGate Devices

ID: bd2c551c-9680-517f-935b-6975274c5651

STIX ID: report--bd2c551c-9680-517f-935b-6975274c5651

Feed Name: Fortinet Blog

Threat Score
70/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

...
...

Fortinet reports an active credential-harvesting campaign dubbed “FortiBleed” that leverages reused credentials and brute-force attacks against internet-facing FortiGate devices with weak password hygiene and no MFA. Fortinet advises immediate actions including terminating admin/VPN sessions, resetting credentials, implementing MFA, upgrading to versions with PBKDF2-hashed admin credentials, validating configurations for unauthorized changes, reviewing logs for suspicious access, and restricting external management access; affected devices should be treated as compromised if unauthorized modifications or IoCs are found.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.