FBI Warns of Ongoing FortiBleed Attacks Locking Out FortiGate VPN Admins
FBI warns of ongoing FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways, locking out legitimate administrators.
Intelligence analysis by Qwen 2.5 (3B)

The FBI is warning about ongoing FortiBleed attacks that are locking out legitimate Fortinet FortiGate firewall and SSL VPN gateway administrators.
Bad guys are using stolen passwords to get into Fortinet's firewalls and lock out the people who are supposed to manage them. They do this by using lots of computers to try different passwords until they find the right one.
Analysis
{"heading":"The FortiBleed Attack Chain","subheading":"Initial Entry Point and Ransomware Affiliates","content":["The FBI has warned that FortiBleed attacks are still active, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways, and locking out legitimate administrators.","Hackers gain access to exposed endpoints by using previously leaked credentials or logins obtained from infostealer logs, credential stuffing, and password spraying attacks.","The attackers then extract additional authentication data from compromised devices and use a distributed GPU cluster running Hashcat and Hashtopolis to crack offline the stolen password hashes."]}
Key points
- FortiBleed attacks are still active and targeting Fortinet FortiGate firewalls and SSL VPN gateways.
- Hackers use stolen credentials and password cracking techniques to gain access.
- The FBI recommends strengthening password security and enforcing Multi-Factor Authentication (MFA).
By strengthening password security and improving firewall management, organizations can better protect against these types of attacks.
If the attackers find a way to bypass the new security measures, they could still gain access to the firewalls and cause further damage.



