FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
Overview
The FBI and the Secret Service have issued a warning regarding the ongoing FortiBleed credential harvesting campaign, which targets Fortinet's FortiGate firewalls and SSL VPN gateways. This campaign has reportedly collected over 86,000 credentials, exploiting weaknesses in reused or leaked passwords and outdated password storage methods. Organizations using Fortinet products need to be vigilant, as attackers can gain unauthorized access to sensitive systems. The persistence of this threat highlights the importance of using strong, unique passwords and implementing robust security measures. Companies are urged to review their security protocols to protect against this active exploitation.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Fortinet FortiGate firewalls, SSL VPN gateways
- Action Required: Implement strong, unique passwords; review and update security protocols; consider applying security patches as they become available.
- Timeline: Ongoing since at least October 2023
Original Article Summary
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
Impact
Fortinet FortiGate firewalls, SSL VPN gateways
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since at least October 2023
Remediation
Implement strong, unique passwords; review and update security protocols; consider applying security patches as they become available.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Fortinet.