Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries
ID: 685d790e-7dc8-5fa5-9847-64f3c4be2411
STIX ID: report--685d790e-7dc8-5fa5-9847-64f3c4be2411
Feed Name: Arctic Wolf Blog
In mid‑June 2026 researchers disclosed “FortiBleed,” an active large‑scale campaign that extracted FortiGate configuration files and cracked stored administrator password hashes, yielding verified credentials for approximately 30,000–75,000 internet‑facing Fortinet firewalls across 194 countries; the issue is driven by legacy SHA‑256 password hashes retained after upgrades. The report documents scale, attribution of operational infrastructure, and prescribes mitigations: rotate credentials, enable MFA, restrict public management access, and enforce PBKDF2 hashing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
