An update on FortiBleed — what’s happening with victim orgs
ID: 31ace8a5-aa9a-5423-bd30-cc0e526b2a28
STIX ID: report--31ace8a5-aa9a-5423-bd30-cc0e526b2a28
Feed Name: DoublePulsar
This report updates on the FortiBleed activity: threat actors scanned and accessed internet-facing FortiGate devices, exported full device configurations, cracked stored password hashes using rented GPU clusters, and are selling/using the harvested credentials to access internal networks (including VPNs and Active Directory). The author provides observed IoCs (exporting IPs and victim lists), describes attacker actions (automated config exports, creation of admin accounts, firewall rule changes, VPN logins), and gives remediation guidance including rebuilding compromised appliances, rotating VPN keys, enforcing MFA, and firmware updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
