US cybersecurity authorities have urged administrators of Fortinet firewalls and gateways to harden their devices after revealing that the FortiBleed campaign is still ongoing.
A warning notice published by the FBI and US Secret Service on October 6 cited SOCRadar figures that FortiBleed has already compromised 86,644 devices across 194 countries.
The campaign targets Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. Ransomware affiliates from INC, Lynx and Payload groups are among those using the compromised credentials stolen in FortiBleed attacks for initial access, it claimed.
“Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials,” the notice read. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets.”
by Infosecurity Magazine – FBI and Secret Service Warn of FortiBleed Lockout Threat



