Ethical Hacking News
FortiBleed, a growing concern for cybersecurity and ransomware threats, has seen tens of thousands of devices compromised across 194 countries. Organizations are urged to take immediate action to protect themselves against the attacks, including restricting management access, terminating active sessions, and enabling multi-factor authentication.
Tens of thousands of devices in 194 countries have been compromised by the FortiBleed campaign.The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways using stolen credentials and infostealer logs.The attackers crack password hashes using GPU-accelerated clusters, leaving organizations vulnerable to lateral movement.The FBI and US Secret Service urge organizations to restrict internet-facing management access, reset passwords, and enable multi-factor authentication.At least 12 confirmed ransomware attacks have been linked to the FortiBleed campaign.The campaign highlights the need for organizations to strengthen password policies and implement robust multi-factor authentication.
The FortiBleed campaign, a growing concern for cybersecurity and ransomware threats, continues to pose a significant challenge for organizations worldwide. According to a recent advisory published by the FBI and US Secret Service, tens of thousands of devices across 194 countries have been compromised, with more ransomware groups becoming involved in the attacks.
The campaign, which targets internet-facing FortiGate firewalls and SSL VPN gateways, uses stolen credentials from earlier breaches and infostealer logs for credential stuffing and password spraying. The attackers then extract password hashes from compromised devices and crack them offline using GPU-accelerated clusters. This sophisticated attack vector has left many organizations vulnerable to lateral movement within their environments, making it increasingly difficult to contain the damage.
The FBI and US Secret Service have urged organizations to take immediate action to protect themselves against the FortiBleed campaign. This includes restricting internet-facing management access, terminating active administrative and VPN sessions, resetting passwords, and enabling phishing-resistant multi-factor authentication. The agencies have also warned against paying ransoms, as this can often encourage further attacks.
The connection between the FortiBleed campaign and ransomware attacks is becoming increasingly clear. According to SOCRadar, at least 12 confirmed ransomware attacks have been linked to the campaign. The agencies have identified the INC/Lynx and Payload ransomware groups as being among the affiliates working with compromised-network access supplied by initial access brokers.
The use of compromised credentials and infostealer logs to crack password hashes is a particularly insidious tactic. It highlights the need for organizations to strengthen their password policies and implement robust multi-factor authentication mechanisms. The use of GPU-accelerated clusters to crack password hashes also underscores the importance of keeping software up to date and patched.
The FortiBleed campaign is a sobering reminder of the ongoing threat posed by ransomware and the need for organizations to remain vigilant. As the threat landscape continues to evolve, it is essential that organizations take proactive steps to protect themselves against the latest attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/FortiBleed-Campaign-A-Growing-Concern-for-Cybersecurity-and-Ransomware-Threats-ehn.shtml
https://www.theregister.com/security/2026/10/07/fortibleed-still-a-bleeding-nuisance-as-fbi-confirms-ongoing-attacks/5301585
Published: Wed Oct 7 06:25:04 2026 by llama3.2 3B Q4_K_M