discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

CISA warns Fortinet customers of a sweeping campaign targeting FortiGate appliances, with 86,644 devices compromised. The threat actor uses a bespoke tool to spray login and password combinations to break into devices.

By Ravie Lakshmanan·Jun 19·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
Image: thehackernews.com

The FortiBleed campaign is a global attack targeting internet-facing Fortinet firewalls and VPN gateways, using methods like brute-force, dictionary attack, and credential stuffing.

Why it matters

The breach touches nearly every sector of the global economy, sparing no industry, and highlights the importance of securing against ongoing malicious activity aimed at thousands of internet-accessible devices.

Imagine you have a lock on your door, but you never changed the default combination. That's what happened with many Fortinet devices, making it easy for hackers to get in. They used a special tool to try many combinations at once, and now they have access to many devices.

Analysis

The Scale of the Breach

The FortiBleed campaign is a massive attack that has compromised 86,644 FortiGate devices, with the majority of compromised credentials being generic admin accounts and built-in Fortinet system accounts. This points to a widespread failure to rename default accounts or rotate factory credentials, giving the attacker a highly reliable target list.

The attack is built around a self-sustaining, two-step approach, where the threat actor attempts a curated list of leaked Fortinet passwords against devices across the internet, and then passively monitors network traffic to collect additional credentials.

The Impact on Organizations

The breach has significant implications for organizations, as it allows the threat actor to gain initial access to enterprise environments. The fact that organization-specific accounts account for 36.7% of the remaining breached credentials suggests that the attacker has also successfully compromised accounts created by the organizations themselves, possibly sourced from prior breaches where passwords were never changed.

The top three impacted sectors are telecom, government, and education, with the most exposures located in India, the U.S., Mexico, Colombia, and Thailand. This highlights the need for organizations to take immediate action to secure their devices and protect against the ongoing malicious activity.

Recommendations for Defense

CISA has outlined several recommendations to defend against the activity, including terminating all active SSL VPN and administrative sessions, resetting all Fortinet VPN and administrative passwords, and enforcing strong password policies. Organizations should also ensure the use of the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials and remove weaker legacy hashes.

Additionally, organizations should review firewall, VPN, authentication, and domain controller logs for signs of suspicious actions, including unauthorized configuration changes. Enabling phishing-resistant MFA on all external gateways and administrative interfaces can also help reduce the attack surface and lock down management.

Key points

  • 86,644 FortiGate devices compromised
  • Generic admin accounts and built-in Fortinet system accounts make up the majority of compromised credentials
  • Threat actor uses a bespoke tool to spray login and password combinations
  • Organizations should take immediate action to secure their devices and protect against the ongoing malicious activity
The Upside

If organizations take immediate action to secure their devices and protect against the ongoing malicious activity, they can prevent further breaches and minimize the impact of the attack. By following best practices, such as regularly rotating security credentials and enabling multi-factor authentication, organizations can reduce the risk of compromise.

The Downside

The breach has already compromised a large number of devices, and the threat actor may have already gained access to sensitive information. If organizations do not take immediate action, they may be vulnerable to further attacks, which could have significant consequences, including data breaches and disruption of critical services.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityfortinetfortigatecredential-stuffingfirewall-securitythreat-intelligencevpn-security

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 19, 2026

Source

thehackernews.com

Share

Topics

securityfortinetfortigatecredential-stuffingfirewall-securitythreat-intelligencevpn-security

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.