techjacksolutions.com • 3h
Fortinet FortiGate: Mass Credential Compromise via FortiBleed Campaign
The "FortiBleed" campaign targets internet-facing Fortinet FortiGate firewalls through the systematic exploitation of vulnerabilities to extract sensitive configuration files. These files contain administrative credential hashes, which threat actors subject to offline cracking attacks to obtain plaintext credentials. The campaign has impacted 86,644 devices across 194 countries, resulting in the compromise of an estimated 30,000 to 75,000 verified administrator accounts. This widespread access enables threat actors to achieve full administrative control over network infrastructure, facilitating lateral movement, data exfiltration, and persistent network compromise within highly sensitive enterprise environments.
Links:techjacksolutions.com, arcticwolf.com, Recordedfuture, Reddit, Fortinet, Dataprise, Labs, Beazley •