惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
Recent Announcements
Recent Announcements
Last Week in AI
Last Week in AI
博客园 - Franky
Microsoft Security Blog
Microsoft Security Blog
Hugging Face - Blog
Hugging Face - Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Vercel News
Vercel News
MyScale Blog
MyScale Blog
大猫的无限游戏
大猫的无限游戏
罗磊的独立博客
H
Help Net Security
月光博客
月光博客
Martin Fowler
Martin Fowler
博客园 - 【当耐特】
宝玉的分享
宝玉的分享
P
Proofpoint News Feed
GbyAI
GbyAI
腾讯CDC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout
https://www.infosecurity-magazine.com/profile/phil-muncaster/ · 2026-06-22 · via www.infosecurity-magazine.com

The UK’s National Cyber Security Centre (NCSC) has released guidance for Fortinet customers impacted by a global credential theft campaign.

A database of around 75,000 credentials stolen from FortiGate firewall and SSL VPN customers was discovered by security researchers last week. Dubbed “FortiBleed,” it features usernames, email addresses and plaintext passwords for organizations including Oracle, Spotify, Toyota and AT&T.

It is understood that credentials on around half of all internet-accessible Fortinet firewalls may have been exposed in this way.

According to Hudson Rock, a firm specialized in infostealer malware, the exposed logins impact customers in 194 countries and are linked to over 21,000 unique domains.

Read more on data leaks: Exclusive: Massive IoT Data Breach Exposes 2.7 Billion Records.

It’s unclear exactly how the targeted devices were originally accessed – potentially by exploiting legacy vulnerabilities in the products, or a novel zero day.

However, it seems that the threat actors first stole configuration data and then brute-forced the passwords contained within.

The NCSC cited “brute-force, dictionary and credential stuffing attempts.”

Reports suggest many organizations have already suffered full network compromise as a result, and any organization featured in the database is at risk.

The leaked information “is formatted in a way which looks like an eCrime gang – e.g. it lists the type of company, their revenue and country,” said cybersecurity researcher, Kevin Beaumont.

“The operation’s footprint is staggering: the attackers executed an estimated 1.16 billion credential attempts against over 320,000 FortiGate targets, alongside an additional 2.1 billion brute-force attempts directed at over 160,000 MSSQL servers,” added Hudson Rock.

NCSC Guidance

The NCSC urged Fortinet customers to use Hudson Rock's or SOCRadar’s FortiBleed checker tools to see if their devices have been affected,and then to look for indicators of compromise (IoCs) such as unauthorized account creation, or unexpected activity in log files.

It then advised impacted organizations to:

  • Isolate compromised devices from the internet and internal networks
  • Report the incident to the government and consider using an assured incident response provider
  • Obtain logs, configs and other artefacts from the device then factory reset it
  • Investigate other edge devices that share credentials with the compromised device 
  • Investigate devices reachable by the compromised device and monitor firewall logs for suspicious activity to ensure no onward compromise has occurred
  • Harden the re-commissioned system by ensuring it’s on the latest version, has strong, unique admin passwords and multi-factor authentication (MFA) applied, and is not exposed to the internet. Users should also enable PBKDF2 for the admin interface