CISA has issued an urgent warning to Fortinet customers following the 'FortiBleed' data leak, which exposed credentials for approximately 74,000 FortiGate firewall and VPN devices worldwide. The leaked data includes plaintext usernames, passwords, and organizational details spanning 194 countries and 21,632 unique domains. Affected organizations include Samsung, Mercedes-Benz, Toyota, AT&T, and numerous government agencies. The operation is linked to a Russian-speaking threat group that allegedly conducted 1.16 billion credential attempts against over 320,000 FortiGate targets. CISA recommends terminating all SSL VPN and admin sessions, resetting passwords, enabling phishing-resistant MFA, switching to PBKDF2 password hashing, and restricting management interfaces from public internet access. Hudson Rock has released a free lookup tool to help organizations check if they are affected.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Credentials for over 73K firewalls exposedData leak linked to Russian-speaking threat groupTest every layer before attackers do
484 Impressions