THE FortiBleed campaign has compromised 30,791 Fortinet firewalls and VPN credentials worldwide, affecting organizations across 194 countries, including banks, hospitals, and telecommunications companies. Identified by SOCRadar, the operation involves automated scanning and credential harvesting, utilizing a list of previously leaked passwords. This self-perpetuating system allows attackers to continually exploit breached devices. No new vulnerabilities are involved; rather, it's a matter of credential reuse.
SOCRadar has urged immediate action, recommending that organizations change passwords, enable two-factor authentication, and maintain up-to-date security measures.