A large-scale hacking campaign dubbed FortiBleed has compromised tens of thousands of Fortinet firewalls and VPNs used by major global enterprises including Accenture, Oracle, Samsung, and Siemens. The attack does not exploit unknown vulnerabilities — instead, hackers use automated scanners to find exposed Fortinet devices and break in using previously leaked passwords. Once inside, compromised devices are used as listening posts to harvest additional credentials, which are fed back into the scanner to compromise more devices. Security firms Hudson Rock and SOCRadar report over 30,000–73,000 unique Fortinet URLs affected, with victims concentrated in India, the US, Taiwan, and Mexico. The group behind the campaign appears to be Russian-speaking.

3m read timeFrom techcrunch.com
Post cover image
153 Impressions