AUTO-UPDATED

CISA Warns of Active Exploitation Following FortiBleed Leak

CISA has issued an emergency alert after researchers discovered a massive credential leak affecting approximately 74,000 Fortinet firewalls and VPN gateways, enabling active exploitation by malicious cyber actors.

Key Points

  • The "FortiBleed" incident involves leaked plaintext credentials for 73,932 unique Fortinet devices across 194 countries.
  • Security researchers Bob Diachenko and Kevin Beaumont confirmed the dataset includes valid login information for major corporations and government agencies.
  • A Russian-speaking threat group reportedly used a 45-GPU cluster to crack authentication hashes and conduct over 1.1 billion credential attempts.
  • The leaked data originated from exported device configurations, suggesting attackers gained prior access to the affected hardware.
  • CISA mandates that organizations reset all administrative passwords, enable phishing-resistant multi-factor authentication, and remove management interfaces from the public internet.
  • Hudson Rock has launched a free lookup tool at hudsonrock.com/fortinet for organizations to verify if their domains are included in the compromised dataset.

Why it Matters

This breach represents a significant threat to global critical infrastructure, as compromised firewall credentials grant attackers deep access to internal corporate and government networks. Because the data includes business intelligence for potential sale, it highlights a sophisticated, organized effort to monetize initial access to high-value targets.
Securityaffairs.com Published by Pierluigi Paganini
Read original