惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
WordPress大学
WordPress大学
博客园 - 【当耐特】
The Cloudflare Blog
B
Blog
Last Week in AI
Last Week in AI
小众软件
小众软件
量子位
S
SegmentFault 最新的问题
V
Visual Studio Blog
博客园 - 叶小钗
美团技术团队
阮一峰的网络日志
阮一峰的网络日志
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
宝玉的分享
宝玉的分享
A
About on SuperTechFans
雷峰网
雷峰网
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
腾讯CDC
MongoDB | Blog
MongoDB | Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Martin Fowler
Martin Fowler

Security

Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers
Act Now! ACSC releases multiple Critical Alerts over Fort...
David Hollingworth · 2026-06-22 · via Security

Russian-speaking hackers have been compromising tens of thousands of Fortinet firewalls and VPN gateways using weak credentials – here’s what you need to know to protect your organisation.

Act Now! ACSC releases multiple Critical Alerts over FortiBleed, as Fortinet releases Situational Analysis report

The Australian Signals Directorate’s Australian Cyber Security Centre has released a pair of Critical Alert: Act Now advisories regarding the widespread compromise of Fortinet Firewalls and VPN Gateways in a campaign widely known as FortiBleed.

“The ASD’s ACSC is aware of public reporting of a widespread malicious campaign against Fortinet Firewalls and VPN gateways, largely utilising exposed credentials and credential-based attacks, leading to potential compromise and further credential exposure,” the ACSC said in its initial June 18 alert, released in the wake of SOCRadar analysis of the ongoing campaign on June 16.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

“Leveraging these credentials could enable malicious actor’s remote access to the devices and connected networks, as well as allow changes to various settings, including security controls.”

According to SOCRadar, the adversary appears to be Russian-speaking and to date, has compromised more than 30,000 devices in 200 countries, including Australia.

“Once a device is compromised, they use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by. Those freshly collected passwords are then fed back into the scanner to compromise even more devices. The system feeds itself,” SOCRadar said in a blog post.

“The password list is not random. It is a carefully assembled collection of credentials leaked from Fortinet devices in earlier incidents, meaning many targets may have never changed their passwords after a prior breach. The attackers know this, and they are counting on it.”

The ACSC reissued its original alert today, on June 22, following the release of updated advice from Fortinet, which was published late last week.

“Fortinet have released a blog post and additional guidance regarding this activity,” the ACSC said.

“Affected organisations should review and monitor Fortinet’s post.”

Fortinet’s Situational Analysis report, published June 19, explains that while this is not based on any new Fortinet vulnerability, the company does believe it involves the reuse of credentials compromised in two previous incidents, dating back to December 2025 and January 2026.

“Fortinet provided detailed guidance at the time of these advisories and we continue to strongly encourage all customers to ensure these remediation steps have been completed,” Fortinet said.

“Upon identifying the incident, we immediately began an investigation, including collaborating with relevant government agencies.”

Fortinet said it is in the process of contacting customers impacted by the campaign, and shared six recommendations that should be immediately implemented on compromised devices:

  1. Terminate all admin and VPN sessions and reset credentials. Terminate all active administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies.
  2. Implement MFA on all administrator and VPN user accounts.
  3. Upgrade to latest versions of 7.4, 7.6, or 8.0. These versions support PBKDF2 hashing of administrator credentials. Follow the guidance to remove older legacy password settings via set login-lockout-upon-weaker-encryption.
  4. Validate configuration. Review firewall and VPN users and other configuration for unauthorised changes. Preferably compare to a known good configuration. Pay particular attention to the addition of unrecognised accounts, such as “forticloud, fortiuser, fortinet-support, fortinet-tech-support,” etc.
  5. Check your logs. Look for unexpected administrator access from an unknown IP and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorised configuration changes.
  6. Reduce your attack surface and lock down management access. Restrict external management of your devices via trusted hosts (good), a local-in policy (better), or remove internet administration altogether (best).

The company also shared details of its FortiGuard Incident Response service, which customers can use to request an investigation into their network.

“Fortinet diligently balances our commitment to the security of our customers and our culture of responsible transparency,” Fortinet concluded.

“We are continuing to investigate this situation and taking actionable steps with the security of our customers as our top priority. Our response and mitigation efforts remain ongoing.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.