discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

CISA warns Fortinet customers of a sweeping campaign targeting FortiGate appliances, with 86,644 devices compromised. The threat actor uses a bespoke tool to spray login and password combinations to break into devices.

By Ravie Lakshmanan·Jun 19·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
Image: thehackernews.com

The FortiBleed campaign is a global attack targeting internet-facing Fortinet firewalls and VPN gateways, using methods like brute-force, dictionary attack, and credential stuffing.

Why it matters

The breach touches nearly every sector of the global economy, sparing no industry, and highlights the importance of securing against ongoing malicious activity aimed at thousands of internet-accessible devices.

Imagine you have a lock on your door, but you never changed the default combination. That's what happened with many Fortinet devices, making it easy for hackers to get in. They used a special tool to try many combinations at once, and now they have access to many devices.

Analysis

The Scale of the Breach

The FortiBleed campaign is a massive attack that has compromised 86,644 FortiGate devices, with the majority of compromised credentials being generic admin accounts and built-in Fortinet system accounts. This points to a widespread failure to rename default accounts or rotate factory credentials, giving the attacker a highly reliable target list.

The attack is built around a self-sustaining, two-step approach, where the threat actor attempts a curated list of leaked Fortinet passwords against devices across the internet, and then passively monitors network traffic to collect additional credentials.

The Impact on Organizations

The breach has significant implications for organizations, as it allows the threat actor to gain initial access to enterprise environments. The fact that organization-specific accounts account for 36.7% of the remaining breached credentials suggests that the attacker has also successfully compromised accounts created by the organizations themselves, possibly sourced from prior breaches where passwords were never changed.

The top three impacted sectors are telecom, government, and education, with the most exposures located in India, the U.S., Mexico, Colombia, and Thailand. This highlights the need for organizations to take immediate action to secure their devices and protect against the ongoing malicious activity.

Recommendations for Defense

CISA has outlined several recommendations to defend against the activity, including terminating all active SSL VPN and administrative sessions, resetting all Fortinet VPN and administrative passwords, and enforcing strong password policies. Organizations should also ensure the use of the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials and remove weaker legacy hashes.

Additionally, organizations should review firewall, VPN, authentication, and domain controller logs for signs of suspicious actions, including unauthorized configuration changes. Enabling phishing-resistant MFA on all external gateways and administrative interfaces can also help reduce the attack surface and lock down management.

Key points

  • 86,644 FortiGate devices compromised
  • Generic admin accounts and built-in Fortinet system accounts make up the majority of compromised credentials
  • Threat actor uses a bespoke tool to spray login and password combinations
  • Organizations should take immediate action to secure their devices and protect against the ongoing malicious activity
The Upside

If organizations take immediate action to secure their devices and protect against the ongoing malicious activity, they can prevent further breaches and minimize the impact of the attack. By following best practices, such as regularly rotating security credentials and enabling multi-factor authentication, organizations can reduce the risk of compromise.

The Downside

The breach has already compromised a large number of devices, and the threat actor may have already gained access to sensitive information. If organizations do not take immediate action, they may be vulnerable to further attacks, which could have significant consequences, including data breaches and disruption of critical services.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityfortinetfortigatecredential-stuffingfirewall-securitythreat-intelligencevpn-security

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 19, 2026

Source

thehackernews.com

Share

Topics

securityfortinetfortigatecredential-stuffingfirewall-securitythreat-intelligencevpn-security

Related

More from this desk

Aug 18·wired.com

The Cop Who Took On Flock

A police officer in Rhode Island discovers that his city has installed Flock Safety cameras, which can identify vehicles by their license plates and other distinguishing features. The officer's concerns about the cameras' potential for mass surveillance lead to a chain of…

Aug 18·bleepingcomputer.com

Microsoft Confirms Outage Affecting Search in Microsoft 365 Apps

Microsoft confirms that some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. The root cause is a recent deployment that causes resource utilization problems.

Aug 18·thehackernews.com

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal, a hardware wallet maker, has disclosed an authorization flaw in an order-tracking plug-in that exposed the data of nearly 40,000 customers. The exposed records included names, email addresses, shipping addresses, phone numbers, and purchase details, but did not i…

Aug 18·bleepingcomputer.com

Microsoft Removes WMIC Tool Used by Cybercriminals

Microsoft has removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. This move aims to improve the operating system's overall security by thwarting a wide range of m…