
FortiBleed Attackers Locking Victims Out of Fortinet Devices
FROM THE PUBLISHER
The FortiBleed credential-harvesting and access-broker campaign is still active, and attackers are locking organizations out of their Fortinet devices. Targeting internet-accessible Fortinet FortiGate firewalls and SSL VPN appliances, the campaign started in June. Fortinet’s analysis of the attacks revealed that the attackers were using previously compromised credentials and brute-force techniques to take over poorly protected devices. Within a week, the attacks hit over 86,000 Fortinet devices in 190 countries, and a Russian initial access broker…
Original reporting by SecurityWeek. Some articles may require a subscription.