Description

A massive cyber attack known as FortiBleed was identified by security experts, leading to the leaking of credentials from at least 73,000 internet-exposed Fortinet and FortiGate virtual private network (VPN) devices around the world. It is claimed that the leaked credentials consisted of usernames, email addresses, and plain-text passwords for various organizations operating within different industries such as the government, telecommunication industry, hospitals, and other critical infrastructures. The investigation revealed that this incident was associated with a threat actor group speaking Russian language, who carried out extensive credential harvesting and brute force activities on Fortinet devices. Security researchers noticed billion authentications on vulnerable Fortinet devices' VPN gateways and noted some indications showing attackers have harvested configuration files as well as taken advantage of the stolen credentials to penetrate further into victim networks. Although it is not known for sure how the credentials have been stolen, security experts opined that this was done through password attack and prior compromises.? For organizations that employ Fortinet technologies, all passwords for their remote access services and administration services must be changed, especially when such accounts are accessible via the internet. Multi-Factor Authentication (MFA), limiting access to management consoles, and analyzing authentication logs will greatly decrease the chances of any kind of breach. Security personnel should also ensure the Fortinet equipment is up to date and log any suspicious activities within the system.?