FBI and Secret Service Warn of FortiBleed Lockout Threat
FBI and Secret Service warn FortiBleed has compromised 86,644 Fortinet devices and can lock out administrators.
The FBI and US Secret Service warned on October 6 that the FortiBleed campaign is still compromising Fortinet FortiGate firewalls and SSL VPN gateways. Citing SOCRadar, the notice says 86,644 devices in 194 countries have already been compromised. Attackers scan exposed portals, then use credential stuffing and password spraying from earlier Fortinet leaks and infostealer logs, crack passwords with Hashcat and Hashtopolis, create new firewall admin accounts, and enumerate Active Directory. Ransomware affiliates from INC, Lynx, and Payload have used the stolen credentials, and victims can be locked out if accounts are disabled or passwords changed.