A dataset dubbed 'FortiBleed' has exposed plaintext credentials for nearly 74,000 Fortinet FortiGate firewall and VPN devices across 194 countries — roughly half of all Fortinet firewalls exposed to the internet. The attack involved no zero-day exploit; instead, attackers used credential stuffing and brute-force techniques at massive scale, including a 45-GPU cluster running over a billion login attempts. High-profile organizations including Oracle, Samsung, Siemens, and a NATO defence contractor appear in the data. At least four organizations were fully compromised, with classified documents stolen from one. Fortinet disputes the data represents a new incident, but researchers say the affected devices differ from prior known leaks. Recommended mitigations include rotating passwords, enforcing MFA, restricting management interfaces to trusted IPs, and auditing logs.

3m read timeFrom thenextweb.com
Post cover image
Table of contents
No flashy zero-day, just industrial password-crackingWhat it does and doesn’t mean
252 Impressions