logo

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

ID: 43244e12-4f3c-5366-b5de-ae160b57613d

STIX ID: report--43244e12-4f3c-5366-b5de-ae160b57613d

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: [email protected] (The Hacker News)

...
...

A global campaign named 'FortiBleed' has compromised 86,644 internet-facing Fortinet FortiGate firewalls and VPN gateways by mass-scanning for remote login endpoints and using credential-stuffing/brute-force against default, leaked, and org-specific credentials; attackers then passively harvested additional credentials to scale the campaign. CISA and other agencies warn customers to reset passwords, terminate sessions, enable MFA, ensure PBKDF2 password storage, and review logs, while vendors note some data may be reshared from prior incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.