FortiBleed Attackers Locking Victims Out of Fortinet Devices
Summary
Attackers are exploiting a vulnerability in Fortinet devices, a flaw dubbed 'FortiBleed,' to lock legitimate users out. The attackers achieve this by creating new administrator accounts and deleting existing ones, along with their passwords.
IFF Assessment
FOE
This article describes an attack that prevents legitimate users from accessing their systems, causing operational disruption and potential data loss for organizations.
Defender Context
Organizations using Fortinet devices should be aware of the 'FortiBleed' attack and the methods attackers use to gain unauthorized access and deny service. Defenders should prioritize patching affected devices and monitoring for suspicious account creation or deletion activities.