www.securityweek.com 6/19/2026, 11:10:16 AM · external

CISA urges action after FortiBleed hits 86k firewalls

CISA urges action after FortiBleed hits 86k firewalls
Developing story campaign 3 articles tracked
FortiBleed credential leak exposes tens of thousands of Fortinet devices
CyberSIXT Evidence Panel
Primary Source cisa.gov

CISA is urging organizations to secure their Fortinet devices due to the FortiBleed campaign, which has compromised over 86,000 firewalls and VPNs. This campaign involves a Russian-speaking threat actor who has compiled a database of working credentials from over 194 countries. Attackers have made approximately 1.16 billion credential attempts targeting FortiGate devices and have compromised several organizations, including critical infrastructure providers. CISA recommends actions such as resetting credentials, enabling multi-factor authentication, and reviewing logs for suspicious activity.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline