惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
博客园_首页
博客园 - 三生石上(FineUI控件)
V
Visual Studio Blog
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
小众软件
小众软件
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
月光博客
月光博客
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
IT之家
IT之家
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recent Announcements
Recent Announcements
M
MIT News - Artificial intelligence
阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It
FortiBleed Attack Exposes Fortinet Firewall Credentials i...
Waqas · 2026-06-18 · via Hackread – Cybersecurity News, Data Breaches, AI and More

A newly reported campaign targeting Fortinet FortiGate firewalls has put exposed VPN and administrator access back in focus, after researchers linked the activity to tens of thousands of verified firewall logins affecting major companies and public sector organizations.

Cybersecurity firm Hudson Rock says the dataset, first identified by researcher Volodymyr “Bob” Diachenko, includes 73,932 unique Fortinet firewall URLs in 194 countries, connected to 21,632 affected domains.

The company has branded the activity “FortiBleed” and launched a free lookup portal for organizations to check whether their domains appear in the dataset.

The names listed in the exposed data include high-profile organizations such as Samsung, Oracle, Foxconn, Comcast, Siemens, Lenovo, Spotify, Sony, and others, according to Hudson Rock and screenshots shared with the research.

The data also appears to include government, telecom, manufacturing, retail, logistics, and critical infrastructure targets.

FortiBleed Attack Exposes Credentials for Tens of Thousands of Fortinet Firewalls
Image credit: Hudson Rock

The campaign does not appear to be a simple password dump. Diachenko’s investigation describes a Russian-speaking, multi-operator group using exposed FortiGate systems, historical credential leaks, and infostealer logs to test access at high volume.

Hudson Rock says the operators ran about 1.16 billion credential attempts against more than 320,000 FortiGate targets, along with 2.1 billion brute-force attempts against more than 160,000 MSSQL servers.

Once a login worked, the attackers recorded it in a verified database. From there, the operation could feed itself, including compromised firewall access, which may allow attackers to monitor VPN or gateway traffic, collect more credentials, and reuse them in later attacks.

Diachenko also reported deeper compromises in Japan, Taiwan, Vietnam, Iraq, and Turkey, including a Turkish NATO defense contractor where classified defense documents were allegedly stolen. Those claims have not yet been independently confirmed by Fortinet in the public material reviewed for this article.

FortiBleed Attack Exposes Credentials for Tens of Thousands of Fortinet Firewalls
Redacted screenshot showing alleged Fortinet firewall login entries, affected domains, FortiGuard IDs, industries, and country codes. (Credit: Bob Diachenko)

The technical concern here is not only weak passwords. Hudson Rock’s analysis says many of the successful credentials were complex passwords that had already been stolen through prior breaches, infostealer infections, or recovered firewall data. In that situation, Password complexity offers little protection in that situation because the attacker is not guessing; they are trying passwords that were already stolen.

Fortinet has previously warned customers that internet-facing FortiGate administration and VPN services require tight access controls, patching, and careful configuration. Its own FortiOS hardening guidance advises administrators to review default passwords, certificates, exposed management ports, and SSL VPN access when deploying or maintaining FortiGate systems.

Organizations using Fortinet devices should treat the report as a reason to move fast, but not panic. The first steps are clear: rotate FortiGate admin and VPN credentials, enforce MFA on all external access, restrict management interfaces to trusted IP ranges, review gateway logs for suspicious logins, remove unused accounts, and verify that FortiOS devices are fully patched.

Hudson Rock’s FortiBleed portal allows organizations to search for affected domains and request disclosure details. Companies that find a match should assume exposed credentials are already in criminal hands and begin containment, password rotation, and log review immediately.