Urgent Alert: FortiBleed Campaign Compromises Admin Credentials on 86,000 Fortinet Firewalls Worldwide
Signal Watch | Fortibleed @channel Just last week, CISA issued an urgent alert about FortiBleed ā it's a reused name for a new campaign that's compromised working admin credentials for more than 86,000 Fortinet firewalls across 194 countries. Here's what makes this one different: no zero-day; no sophisticated exploit; Just 1.16 billion brute force password attempts against devices that were "patched" but still had weak password hashes sitting in config files. So what was the vulnerability? When organisations upgraded FortiOS firmware, the new password security only activated if an admin logged in afterward. Thousands never did. Those old SHA-256 hashes stayed intact for years ā until someone built a 45-GPU cracking cluster and broke them at industrial scale. The compromised credentials are now packaged with company revenue data and sector classifications. That's the format ransomware affiliates use to pick targets. If you have a Fortinet device, it's probably best to assume you're in the dataset and consider following CISA's advice:
Terminate all active SSL VPN and administrator sessions.
Reset all Fortinet administrative and VPN passwords.
Review logs for:
unusual VPN logins,
administrator logins,
configuration changes,
lateral movement.
Enable phishing-resistant MFA wherever possible.
Ensure management interfaces are not exposed directly to the Internet.
Keep FortiOS fully patched, even though this campaign isn't centred on a new software vulnerability.
cisa.gov/news-events/ā¦/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
