Minacce · 2 ore fa
FBI e USSS dicono che FortiBleed è ancora attivo e ha già accumulato più di 86.644 credenziali valide di dispositivi Fortinet. Per chi gestisce FortiGate e SSL VPN esposti a Internet, non si tratta più di un singolo furto di password: è una fonte continua di accessi funzionanti.
La campagna sfrutta password riusate o già trapelate e l’archiviazione legacy SHA-256 degli account amministrativi per raccogliere e poi rompere le credenziali in massa. Una volta dentro, gli attaccanti intercettano il traffico di autenticazione sul dispositivo, ricavano altri segreti e usano anche cookie di sessione rubati per mantenere l’accesso dopo un reset.
La conseguenza è che la correzione del solo problema iniziale non basta a riprendere il controllo. Per gli ambienti che affidano al FortiGate l’accesso remoto, l’esposizione può restare aperta finché credenziali, sessioni e account amministrativi già compromessi non vengono trattati come persi.
6 fonti che coprono questa storia
FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users
An initial access broker is working with various ransomware groups in a global campaign.
Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, U.S.
The Record from Recorded Future
FBI, Secret Service add to warnings of FortiBleed credential stealing campaign
Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S.
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
FBI and USSS warn FortiBleed remains active, using stolen credentials and traffic sniffing to harvest Fortinet authentication data.
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
Tens of thousands more victims and more ransomware groups getting in on the act
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
The FBI and Secret Service warn that the FortiBleed campaign has targeted over 400,000 Fortinet devices, locking users out and enabling ransomware attacks.
Part of the PlainSec briefing for 2026-10-07