FBI and Secret Service Warn of Ongoing FortiBleed Attacks Compromising Over 86,000 Fortinet Devices
The FBI and U.S. Secret Service have issued a joint advisory warning that FortiBleed attacks are continuing to compromise Fortinet devices, with over 86,644 devices affected across 194 countries. These attacks primarily target internet-facing FortiGate firewalls and SSL VPN gateways. Fortinet has clarified that the activity involves the reuse of previously stolen credentials and brute-force attacks, rather than a newly discovered vulnerability. Attackers are scanning exposed FortiGate VPN portals, testing credentials from past data leaks and infostealer logs, and exploiting legacy SHA-256 password storage to crack password hashes offline. Once unauthorized access is gained, intruders can create new administrator accounts, investigate Active Directory, and attempt to access other systems. In some instances, attackers have locked legitimate administrators out of their devices by changing or deleting their accounts while retaining their own access. The advisory emphasizes that simply patching devices may not ...