By Interestana AI Editorial — AI-drafted, human-overseen. How we report
FBI Warns FortiBleed Campaign Continues Active Threat

The U.S. Federal Bureau of Investigation (FBI) and the U.S. Secret Service (USSS) issued a joint warning on Tuesday, March 19, 2024, highlighting that the FortiBleed credential harvesting campaign continues to pose an active threat. This campaign specifically targets internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. The threat actors are exploiting vulnerabilities related to reused or leaked credentials and legacy SHA-256 password storage mechanisms within these devices. This exploitation allows them to gain unauthorized access to sensitive network information. The campaign has been notably successful, amassing a significant number of credentials from compromised Fortinet devices. According to the agencies' joint advisory, the FortiBleed campaign has already harvested 86,644 credentials from Fortinet devices. These credentials provide attackers with access to the internal networks protected by these security appliances, potentially leading to further cyber intrusions and data breaches. The advisory emphasizes that the threat actors are actively exploiting these weaknesses, indicating a persistent and evolving attack strategy. The FBI and USSS are urging organizations utilizing Fortinet FortiGate devices to take immediate action to mitigate the risks associated with this campaign. Recommended mitigation steps include implementing multi-factor authentication (MFA) for all remote access, ensuring that all devices are running the latest firmware versions, and regularly reviewing access logs for any suspicious activity. Furthermore, organizations are advised to reset all user credentials and conduct thorough security audits of their network infrastructure. The campaign's reliance on credential stuffing and exploitation of older security protocols underscores the importance of robust password policies and regular security updates. Fortinet, a leading provider of cybersecurity solutions, offers a range of products designed to protect networks from various threats, including firewalls, VPNs, and endpoint security solutions. The FortiGate firewall is a widely deployed network security appliance that provides unified threat management capabilities, including intrusion prevention, web filtering, and application control. The SSL VPN feature allows remote users to securely access internal network resources. The success of the FortiBleed campaign in harvesting a large volume of credentials highlights a critical vulnerability in how some organizations manage and protect user authentication information, particularly when legacy systems or weak password practices are in place. The agencies have not disclosed the specific identities of the threat actors involved in the FortiBleed campaign, but the sophisticated nature of the operation suggests a well-resourced and organized group. The ongoing nature of the threat necessitates continuous vigilance and proactive security measures from all organizations relying on Fortinet technology.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.