惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
博客园 - 司徒正美
D
Docker
B
Blog
V
Visual Studio Blog
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
S
SegmentFault 最新的问题
小众软件
小众软件
J
Java Code Geeks
美团技术团队
腾讯CDC
MyScale Blog
MyScale Blog
爱范儿
爱范儿
H
Help Net Security
宝玉的分享
宝玉的分享
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 三生石上(FineUI控件)
博客园 - 【当耐特】

CSO Online

New malware turns Linux systems into P2P attack networks Poisoned truth: The quiet security threat inside enterprise AI Train like you fight: Why cyber operations teams need no-notice drills Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS
FortiBleed campaign exposes 75,000 Fortinet firewalls wor...
Shweta Sharma · 2026-06-18 · via CSO Online

Researchers say threat actors harvested FortiGate credentials at scale, exposing organizations in 194 countries to potential long-term network compromise.

A massive credential-compromise campaign dubbed “Fortibleed” has been found to expose tens of thousands of Fortinet devices worldwide, with researchers warning of persistent attacker access to affected enterprise environments.

The campaign was first flagged by security researcher Volodymyr Diachenko, who posted on LinkedIn about finding an attacker-controlled list of potentially working FortiGate passwords collected “through various means.”

Further details came from SOCRadar after its team independently discovered an operational server, which belonged to an unnamed threat actor and contained a list of stolen FortiGate passwords, tools, automation infrastructure, victim list, and some telling information about who could be behind the attack.

“Attribution is ongoing, but the operational fingerprints are clear,” SOCRadar researchers said in a blog post, adding that the tooling and targeting choices are consistent with Russian-speaking threat actors.

According to independent analyses, including by SOCRadar, Hudson Rock, and security researcher Kevin Beaumont, the threat actors systematically collected configuration files from internet-facing Fortinet FortiGate firewalls and used them to recover working administrator credentials. The initial access vector is presently unknown.

CEO of watchTowr Benjamin Harris said the campaign is consistent with what he has been seeing lately. “The uncomfortable reality is that modern exploitation isn’t always about immediate impact,” he said. “It’s about harvesting data that retains value long after the underlying vulnerability has been patched.”

These credentials were likely accumulated over time by exploiting many vulnerabilities affecting sensitive, externally facing Fortinet applications, he added.

Fortinet did not immediately respond to CSO’s request for comments.

Cracked passwords, global reach

While SOCRadar initially reported that the dataset contained working login credentials for over 30,791 devices, further analysis by Beaumont, along with Hudson Rock, placed the affected devices at 75000, about 50% of the total internet-facing Fortinet firewalls found on Shodan.

Researchers found affected devices across 194 countries, spanning more than 21000 domains.

The dataset reportedly contains a mix of administrative and SSL VPN credentials recovered from compromised configuration files. Researchers said the operation is highly automated, allowing threat actors to collect, process, and crack credential material at a very large scale.

SOCRadar found the top affected countries to be India, the US, and Mexico, with a little under 12000 compromised credentials between them. A credential-type breakdown revealed Organization-specific credentials to be most probed, indicating enterprise targeting.

Explaining the potential impact, Beaumont said the threat actors “can log in remotely and gain remote access to the firewall — and so the network.” They can also change settings, including security controls, and make backdoor users, he added.

Old Hashes, new problems

Additional investigation into the campaign highlighted why some Fortinet deployments proved easier to crack than others.

Researchers noted that many affected systems stored administrator credentials using older hashing approaches that were significantly less resistant to offline password-cracking attacks than more recent implementations.

“Fortinet introduced PBKDF2-based password hashing for administrator credentials in FortiOS 7.2.11, 7.4.8, and 7.6.1, replacing the legacy SHA-256-based storage mechanism,“ Arctic Wolf researchers explained in a blog post. “However, when upgrading from earlier versions, existing administrator passwords remain stored as SHA-256 hashes until the corresponding administrator successfully logs in following the upgrade.”

This could be leading to many organizations continuing to store admin credentials using older SHA-256 with Salt hashing mechanisms, they noted.

Defenders told to assume credential exposure

Researchers urged organizations to assume that credentials contained in exposed FortiGate configuration files have been compromised and to immediately rotate affected administrative and VPN passwords.

Additional recommendations include enforcing multi-factor authentication (MFA), restricting internet access to management interfaces, and reviewing devices for signs of unauthorized access.

Upgrading to supported FortiOS versions and replacing weaker or reused passwords was also advised. “After upgrading FortiOS, require all administrators to log in to the firewall at least once: this will automatically set the encryption to PBKDF2,” the researchers said.

Admin passwords can also be manually updated by using a super_admin account, they noted.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.