FortiBleed Attack Campaign Exploiting Fortinet Firewalls and VPNs – FBI Warns
FBI warns FortiBleed compromised over 86,000 Fortinet firewalls and VPNs in 194 countries.
The FBI and U.S. Secret Service warned that the ongoing FortiBleed campaign is compromising internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, reportedly affecting more than 86,644 devices across 194 countries. It is not a single new Fortinet vulnerability: operators reuse leaked or weak credentials, crack legacy SHA-256 hashes, and sell verified access. After entry they may create administrator accounts, disable or delete legitimate admins, and enumerate Active Directory. The advisory links the activity to initial-access brokers supporting INC/Lynx and Payload ransomware.