FortiBleed Attackers Locking Victims Out of Fortinet Devices

Summary

Attackers are exploiting a vulnerability in Fortinet devices, a flaw dubbed 'FortiBleed,' to lock legitimate users out. The attackers achieve this by creating new administrator accounts and deleting existing ones, along with their passwords.

IFF Assessment

FOE

This article describes an attack that prevents legitimate users from accessing their systems, causing operational disruption and potential data loss for organizations.

Defender Context

Organizations using Fortinet devices should be aware of the 'FortiBleed' attack and the methods attackers use to gain unauthorized access and deny service. Defenders should prioritize patching affected devices and monitoring for suspicious account creation or deletion activities.

Read Full Story →