FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

Summary

The FBI and Secret Service have issued a warning that the FortiBleed credential harvesting campaign is still active. This campaign targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways by exploiting reused or leaked credentials.

IFF Assessment

FOE

The FortiBleed campaign poses a threat to organizations by stealing credentials, which can lead to unauthorized access and further compromise.

Defender Context

Organizations using Fortinet FortiGate devices should be aware of the ongoing FortiBleed campaign. Defenders should prioritize ensuring strong, unique passwords, implementing multi-factor authentication, and monitoring for any signs of credential compromise or unauthorized access attempts.

Read Full Story →