惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
T
Tailwind CSS Blog
V
V2EX
阮一峰的网络日志
阮一峰的网络日志
H
Help Net Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
腾讯CDC
GbyAI
GbyAI
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
A
About on SuperTechFans
L
LangChain Blog
Engineering at Meta
Engineering at Meta
F
Fortinet All Blogs
G
Google Developers Blog
The Cloudflare Blog
云风的 BLOG
云风的 BLOG
D
Docker
博客园 - 聂微东
博客园 - 司徒正美
Recent Announcements
Recent Announcements
MyScale Blog
MyScale Blog
U
Unit 42

Cyber Daily News

Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure OpenAI partners with PwC to assist CFOs with AI agents Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay APRA warns of cyber and governance risk due to lagging AI risk management Op-Ed: Australia’s next budget must treat cyber resilience as essential infrastructure Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers Attackers increasingly turning to trusted security tools to compromise Aussie victims Exclusive: Champion Homes confirms customer data compromised in “cyber event” Australia, Japan commit to partnership to meet cyber security challenges & strengthen cyber defences NSW Treasury cyber incident contained, impact no longer ‘significant’ Report: AI-based data incidents on the rise in Australia WA rental scam surge: Tenants targeted with fake $500 discount trap Aussie Information Commissioner launches Privacy Awareness Week 2026 Unregistered branded text messages to be labelled ‘Unverified’ from 1 July US Federal Reserve outlines AI's influence on the finance sector Exclusive: Major Australian jewellery brand confirms cyber incident Australian government establishes new Cyber Incident Review Board Watch this! Komari server monitor tool abused by hackers Act Now! ACSC warns of active exploitation of cPanel & WHM critical vulnerability Exclusive: Kiwi electrical contractor confirms cyber attack
Act Now! ACSC releases multiple Critical Alerts over Fort...
David Hollingworth · 2026-06-22 · via Cyber Daily News

Russian-speaking hackers have been compromising tens of thousands of Fortinet firewalls and VPN gateways using weak credentials – here’s what you need to know to protect your organisation.

Act Now! ACSC releases multiple Critical Alerts over FortiBleed, as Fortinet releases Situational Analysis report

The Australian Signals Directorate’s Australian Cyber Security Centre has released a pair of Critical Alert: Act Now advisories regarding the widespread compromise of Fortinet Firewalls and VPN Gateways in a campaign widely known as FortiBleed.

“The ASD’s ACSC is aware of public reporting of a widespread malicious campaign against Fortinet Firewalls and VPN gateways, largely utilising exposed credentials and credential-based attacks, leading to potential compromise and further credential exposure,” the ACSC said in its initial June 18 alert, released in the wake of SOCRadar analysis of the ongoing campaign on June 16.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

“Leveraging these credentials could enable malicious actor’s remote access to the devices and connected networks, as well as allow changes to various settings, including security controls.”

According to SOCRadar, the adversary appears to be Russian-speaking and to date, has compromised more than 30,000 devices in 200 countries, including Australia.

“Once a device is compromised, they use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by. Those freshly collected passwords are then fed back into the scanner to compromise even more devices. The system feeds itself,” SOCRadar said in a blog post.

“The password list is not random. It is a carefully assembled collection of credentials leaked from Fortinet devices in earlier incidents, meaning many targets may have never changed their passwords after a prior breach. The attackers know this, and they are counting on it.”

The ACSC reissued its original alert today, on June 22, following the release of updated advice from Fortinet, which was published late last week.

“Fortinet have released a blog post and additional guidance regarding this activity,” the ACSC said.

“Affected organisations should review and monitor Fortinet’s post.”

Fortinet’s Situational Analysis report, published June 19, explains that while this is not based on any new Fortinet vulnerability, the company does believe it involves the reuse of credentials compromised in two previous incidents, dating back to December 2025 and January 2026.

“Fortinet provided detailed guidance at the time of these advisories and we continue to strongly encourage all customers to ensure these remediation steps have been completed,” Fortinet said.

“Upon identifying the incident, we immediately began an investigation, including collaborating with relevant government agencies.”

Fortinet said it is in the process of contacting customers impacted by the campaign, and shared six recommendations that should be immediately implemented on compromised devices:

  1. Terminate all admin and VPN sessions and reset credentials. Terminate all active administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies.
  2. Implement MFA on all administrator and VPN user accounts.
  3. Upgrade to latest versions of 7.4, 7.6, or 8.0. These versions support PBKDF2 hashing of administrator credentials. Follow the guidance to remove older legacy password settings via set login-lockout-upon-weaker-encryption.
  4. Validate configuration. Review firewall and VPN users and other configuration for unauthorised changes. Preferably compare to a known good configuration. Pay particular attention to the addition of unrecognised accounts, such as “forticloud, fortiuser, fortinet-support, fortinet-tech-support,” etc.
  5. Check your logs. Look for unexpected administrator access from an unknown IP and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorised configuration changes.
  6. Reduce your attack surface and lock down management access. Restrict external management of your devices via trusted hosts (good), a local-in policy (better), or remove internet administration altogether (best).

The company also shared details of its FortiGuard Incident Response service, which customers can use to request an investigation into their network.

“Fortinet diligently balances our commitment to the security of our customers and our culture of responsible transparency,” Fortinet concluded.

“We are continuing to investigate this situation and taking actionable steps with the security of our customers as our top priority. Our response and mitigation efforts remain ongoing.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.