Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
FBI and Secret Service say FortiBleed still compromises Fortinet VPNs, locking out owners and enabling ransomware affiliates.
The FBI and U.S. Secret Service warned that FortiBleed, a credential-compromise campaign against Fortinet firewalls and VPN gateways, remains active. Attackers use stolen credentials to reach exposed devices, create administrator accounts, and change or disable passwords so legitimate owners are locked out. SOCRadar previously verified 86,644 compromised devices across 194 countries and later estimated 400,000 to 450,000 firewalls were targeted. The alert says initial access brokers are providing that access to ransomware affiliates, including INC/Lynx and Payload.