FBI warns FortiBleed actors compromised 86,644 FortiGate devices worldwide

Moyen · Hackread ·

En bref

  • FBI warns of ongoing attacks by FortiBleed actors against FortiGate appliances.
  • SOCRadar reports 86,644 devices compromised across 194 countries.
  • No specific CVEs have been linked to this campaign yet.
  • K-12 and government networks using FortiGate should review configurations and logs.

The Federal Bureau of Investigation has issued an alert about a threat cluster dubbed FortiBleed. These actors are actively aiming at and breaching FortiGate security appliances. The warning comes as SOCRadar, a threat intelligence firm, published data showing the scale of the problem.

According to SOCRadar, tens of thousands of FortiGate devices — specifically 86,644 — have been compromised. These compromised machines are spread across 194 nations, indicating a global campaign rather than a targeted one. The affected devices include firewalls and VPN gateways that many organizations rely on for perimeter defense.

For K-12 school districts and government agencies in New Brunswick, this matters because FortiGate products are common in network edge deployments. If an attacker gains control of such a device, they can intercept traffic, pivot into internal networks, or disable security controls. Even without a specific CVE, the compromise likely stems from weak credentials, missing patches, or misconfigurations.

The FBI's warning underscores the need for immediate review. Fortinet has not released a new CVE for this activity, so signature-based detection may be insufficient. SOCRadar's reporting highlights that the attackers are not just targeting but successfully compromising devices at scale. IT teams should assume that any internet-exposed FortiGate could be at risk.

What to watch: continue monitoring Fortinet advisories and FBI updates. Check for unusual outbound connections, unauthorized configuration changes, or new admin accounts on FortiGate devices. Enable logging and multi-factor authentication. Given the medium severity, prioritize patching and credential hygiene over emergency measures, but do not ignore the threat.

À faire maintenant

  1. Inventory all FortiGate devices, prioritizing internet-facing ones, and verify their firmware versions.
  2. Immediately change default or weak administrative credentials and enable multi-factor authentication for all admin accounts.
  3. Apply the latest available Fortinet firmware updates, even without a specific CVE, as they may include security hardening.
  4. Review logs for indicators of compromise: unusual login attempts, new admin users, or unexpected outbound connections.
  5. Disable or restrict remote management interfaces (SSL-VPN, admin GUI) from public internet access where operationally feasible.
  6. Monitor FBI and Fortinet advisories, and consider threat hunting using SOCRadar's published indicators.
  7. Segment network access so that a compromised FortiGate cannot freely reach internal systems or sensitive data.

Source originale

Hackread

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber