惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
量子位
GbyAI
GbyAI
腾讯CDC
T
Tailwind CSS Blog
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
D
Docker
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
The GitHub Blog
The GitHub Blog
Microsoft Security Blog
Microsoft Security Blog
Stack Overflow Blog
Stack Overflow Blog
Hugging Face - Blog
Hugging Face - Blog
小众软件
小众软件
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
N
Netflix TechBlog - Medium
Jina AI
Jina AI
IT之家
IT之家
Y
Y Combinator Blog

Security

Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers
No time to FortiBleed! Russian hackers compromise more th...
David Hollingworth · 2026-06-18 · via Security

Security analysts uncover large-scale compromise of Fortinet firewalls and VPN gateways, and it’s already impacted more than 73,000 credentials.

No time to FortiBleed! Russian hackers compromise more than 30k Fortinet firewalls in almost 200 countries, including Australia

Security researchers at SOCRadar have outlined the details of a massive and ongoing campaign targeting Fortinet firewalls and VPN devices, which analysts have already dubbed FortiBleed.

Alarmingly, the operation – which SOCRadar attributes to a Russian-speaking adversary – appears to be fully automated, and is based upon a curated list of known passwords.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

The attackers scan for Fortinet devices, and methodically test each one, recording the passwords that gain access to each device.

“Once a device is compromised, they use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by. Those freshly collected passwords are then fed back into the scanner to compromise even more devices. The system feeds itself,” SOCRadar said in a June 16 blog post.

“The password list is not random. It is a carefully assembled collection of credentials leaked from Fortinet devices in earlier incidents, meaning many targets may have never changed their passwords after a prior breach. The attackers know this, and they are counting on it.”

So far, SOCRadar has found 30,791 compromised devices, running across 8,316 unique domains, and based in 194 countries around the world.

Most of the victims tend to be from NATO countries, and while SOCRadar is still investigating, it says “the operational fingerprints are clear”.

However, two Australian entities appear in SOCRadar’s list of the top 50 targeted organisations.

Perhaps the most disappointing aspect of this mass compromise is that the most commonly compromised passwords remain some of the most commonly used.

“This points directly to a widespread failure to rename default accounts or rotate factory credentials, giving the attacker a highly reliable target list before any brute force was even needed,” SOCRadar said.

Targets in government and the education sector feature prominently, but telecommunications firms make up the bulk of the compromised credentials.

Benjamin Harris, CEO and founder of cyber security firm watchTowr, observed that “73,000+ Fortinet VPN credentials don't just appear overnight”.

“Attackers are moving faster than defenders, exploiting internet-facing appliances within hours, extracting credentials and sensitive data, and returning later, even after the device has been patched. A vulnerability may exist only for a short time, but stolen credentials can provide access for months or years,” Harris told Cyber Daily.

“This serves as yet another reminder that ‘patch faster’ is no longer sufficient advice. If this incident resulted from the rapid exploitation of earlier Fortinet CVEs, the real issue isn’t the bug itself; it’s the access attackers gain before organisations can even respond.”

Harris noted that while the source of the data remains unknown, it’s most likely that the credentials were harvested over a long period, exploiting numerous vulnerabilities in internet-facing Fortinet applications.

“The uncomfortable reality is that modern exploitation isn't always about immediate impact. It's about harvesting data that retains value long after the underlying vulnerability has been patched,” Harris said.

“And the pattern repeats. A vulnerability is exploited, credentials and configuration data are collected, and the incident fades from view.

“Months later, the vulnerability is patched, and defenders believe the risk has passed. The bug was temporary. The access wasn't.”

You can read SOCRadar’s full analysis, and a tool to check for compromise, here. For now, however, here is SOCRadars’ advice.

“SOCRadar rates this campaign Critical. The single most important step: change every password on every Fortinet device your organisation operates, including VPN accounts and admin accounts,” SOCRadar said.

“Do it today.

“Then enable two-factor authentication, review your login history, and restrict admin access so it cannot be reached from the open internet.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.