CISA is urging organizations to secure their Fortinet devices due to the FortiBleed campaign, which has compromised over 86,000 firewalls and VPNs. This campaign involves a Russian-speaking threat actor who has compiled a database of working credentials from over 194 countries. Attackers have made approximately 1.16 billion credential attempts targeting FortiGate devices and have compromised several organizations, including critical infrastructure providers. CISA recommends actions such as resetting credentials, enabling multi-factor authentication, and reviewing logs for suspicious activity.
CISA urges action after FortiBleed hits 86k firewalls
CyberSIXT Evidence Panel
Primary Source
cisa.gov
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
FortiBleed Spray Hits Thousands Amid WordPress Malware Surge
cybersixt.com
-
CISA warns of FortiBleed credential leak exposing 74,000 devices
cybersixt.com
-
CISA urges action after FortiBleed hits 86k firewalls
www.securityweek.com