logo

Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries

ID: 685d790e-7dc8-5fa5-9847-64f3c4be2411

STIX ID: report--685d790e-7dc8-5fa5-9847-64f3c4be2411

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-18

...
...

In mid‑June 2026 researchers disclosed “FortiBleed,” an active large‑scale campaign that extracted FortiGate configuration files and cracked stored administrator password hashes, yielding verified credentials for approximately 30,000–75,000 internet‑facing Fortinet firewalls across 194 countries; the issue is driven by legacy SHA‑256 password hashes retained after upgrades. The report documents scale, attribution of operational infrastructure, and prescribes mitigations: rotate credentials, enable MFA, restrict public management access, and enforce PBKDF2 hashing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.