74,000 Fortinet firewall credentials exposed in FortiBleed data leak
ID: 0f8b195f-fb62-5516-a32e-b00de287a88f
STIX ID: report--0f8b195f-fb62-5516-a32e-b00de287a88f
Feed Name: Help Net Security
A Russian-speaking cybercriminal group harvested and exposed credentials from configuration files for about 73,932 Fortinet firewalls and VPN gateways worldwide (dubbed “FortiBleed”), using intercepted SSL VPN authentication hashes cracked on a 45-GPU cluster and leveraging exposed FortiGate management interfaces; many high-profile organizations and government entities are affected, with confirmed compromises and exfiltration in some cases. The report urges immediate remediation (rotate credentials, enforce MFA, upgrade FortiOS, remove management interfaces from the internet) and provides a lookup tool for affected organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
