We need answer only headline <=90 chars. Need factual, no five-word sequence with external source. Need craft. Facts: FBI, US Secret Service

Medium · Security Affairs ·

Key points

  • FBI and Secret Service issue joint advisory on FortiBleed activity targeting Fortinet FortiGate appliances.
  • Attackers harvest credentials, compromise devices, and lock out administrators.
  • Over 86,000 devices in 194 countries are affected.
  • No CVEs have been assigned; remediation focuses on credential resets and access controls.

The FBI and US Secret Service have released a joint advisory warning about an active campaign by the group known as FortiBleed. The operators are targeting Fortinet's FortiGate devices, harvesting login credentials, compromising appliances, and locking administrators out of their own systems. The scale is substantial: more than 86,000 devices across 194 nations are believed to be impacted.

Any organization using FortiGate firewalls or VPN gateways is at risk, with government, education, and critical infrastructure sectors particularly exposed. Administrators may find themselves unable to access devices, while stolen credentials could give attackers persistent footholds. The lack of a specific CVE means this is not a traditional patchable vulnerability but rather an exploitation of weak configurations or authentication gaps.

The joint advisory signals a coordinated federal response, underlining the seriousness for public-sector networks. Credential theft can quickly escalate into data breaches, ransomware, or lateral movement. Because FortiGate devices often sit at the network edge, a compromise there can open doors to the entire internal environment.

Context: FortiGate appliances are widely deployed, and the absence of a CVE means standard vulnerability management won't suffice. Instead, IT teams must prioritize hardening, monitoring, and credential hygiene. The advisory likely includes indicators of compromise and attacker tactics. What to watch: follow federal updates, monitor for unusual login attempts and lockout events, and watch for new guidance from Fortinet. Proactive measures are essential to avoid becoming part of the statistics.

What to do now

  1. Immediately audit all FortiGate devices for unauthorized admin accounts or configuration changes.
  2. Reset credentials for every administrative user and enforce multi-factor authentication without exception.
  3. Review authentication logs for suspicious attempts, especially from foreign IPs, and investigate any lockout events.
  4. Restrict management interface access to trusted IP ranges and disable unnecessary remote administration.
  5. Apply the latest firmware updates from Fortinet and follow the joint advisory's specific mitigation guidance.
  6. Monitor for indicators of compromise listed in the advisory and consider temporary network segmentation for affected devices.

Original source

Security Affairs

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news