Description

Security researchers have identified a sophisticated attack campaign dubbed FortiBleed, targeting vulnerable Fortinet security appliances to harvest credentials and gain unauthorized access to enterprise networks. The campaign exploits weaknesses in internet-facing Fortinet devices, allowing threat actors to extract authentication data, session information, and administrative credentials that can later be used to compromise internal systems. Researchers warn that organizations relying on FortiGate firewalls and related Fortinet products are at increased risk if affected devices remain unpatched or improperly secured. The attack leverages vulnerabilities and exposed management interfaces on Fortinet appliances to capture sensitive authentication information from users and administrators. Once attackers gain access to the device, they can collect usernames, passwords, VPN credentials, session tokens, and configuration data stored within the system. Researchers observed that stolen credentials are often used to establish persistent access, bypass perimeter defenses, and facilitate lateral movement within victim environments. In some cases, compromised credentials also enable attackers to access remote access services, cloud resources, and internal applications connected to the affected infrastructure. Investigations revealed that threat actors employ automated scanning tools to identify vulnerable Fortinet deployments exposed to the internet. Following successful exploitation, attackers deploy custom scripts and credential-harvesting mechanisms designed to extract and exfiltrate sensitive data while minimizing detection. The campaign highlights the strategic value of network security appliances as targets, since compromise of these systems can provide visibility into user authentication processes and critical network operations. Researchers emphasize that organizations should immediately review Fortinet device configurations, apply security updates, and monitor for indicators of compromise. Given the widespread use of Fortinet products across enterprises, government agencies, healthcare organizations, and managed service providers, successful exploitation could have significant operational and security consequences