FBI: FortiBleed attackers can lock organizations out of their own firewalls
Summary
The FBI has released new details regarding the "FortiBleed" campaign, revealing that attackers can lock organizations out of their own Fortinet firewalls. The campaign, which has affected over 80,000 devices globally, involves attackers gaining administrative access, creating new accounts, and potentially deleting or changing existing ones to prevent defender access and facilitate lateral movement. This access has also been offered to ransomware groups.
IFF Assessment
The article details how attackers are gaining persistent access to critical network infrastructure and using it to lock defenders out, which is detrimental to organizational security.
Defender Context
This campaign highlights the critical need for organizations to monitor their network perimeter devices for unauthorized access and configuration changes. Defenders should ensure they have robust incident response plans in place to regain control of compromised systems and understand the potential for attackers to deny access to essential security tools.