A massive cyber attack known as FortiBleed was identified by security experts, leading to the leaking of credentials from at least 73,000 internet-exposed Fortinet and FortiGate virtual private network (VPN) devices around the world. It is claimed that the leaked credentials consisted of usernames, email addresses, and plain-text passwords for various organizations operating within different industries such as the government, telecommunication industry, hospitals, and other critical infrastructures. The investigation revealed that this incident was associated with a threat actor group speaking Russian language, who carried out extensive credential harvesting and brute force activities on Fortinet devices. Security researchers noticed billion authentications on vulnerable Fortinet devices' VPN gateways and noted some indications showing attackers have harvested configuration files as well as taken advantage of the stolen credentials to penetrate further into victim networks. Although it is not known for sure how the credentials have been stolen, security experts opined that this was done through password attack and prior compromises.? For organizations that employ Fortinet technologies, all passwords for their remote access services and administration services must be changed, especially when such accounts are accessible via the internet. Multi-Factor Authentication (MFA), limiting access to management consoles, and analyzing authentication logs will greatly decrease the chances of any kind of breach. Security personnel should also ensure the Fortinet equipment is up to date and log any suspicious activities within the system.?
Security researchers have uncovered a sophisticated malware campaign leveraging a China-themed loader chain to distribute multi-stage malware through politically themed decoy docum...
Microsoft has disclosed details of a cryptocurrency-focused malware campaign targeting Windows users since February 2026. The operation centers on clipper malware, a threat designe...
A critical security vulnerability identified as CVE-2023-6875 has been discovered in the widely used POST as in the POST SMTP Mailer plugin versions up to 2.8.7 and is caused by an...