FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday, based on information published by cyberscoop.
The FortiBleed campaign allows attackers to gain access to Fortinet devices, disable accounts, or change passwords, potentially locking legitimate users out of their systems. This necessitates remediation beyond standard patching and password resets. The FBI and Secret Service alert highlights that the attack chain has been observed as an initial entry point for ransomware affiliates, including INC/Lynx and Payload.
Initially, SOCRadar verified over 86,000 compromised devices, with later investigations suggesting over 400,000 to 450,000 firewalls were targeted. The agencies recommend that Fortinet customers restrict external management, reset credentials, implement multifactor authentication, review user accounts for unauthorized changes, and examine logs for lateral movement. They are also seeking information and indicators of compromise from affected organizations.
Source: cyberscoop
