Vulnerabilità · 99 giorni fa
FortiBleed diventa un magazzino di credenziali operative Il cambio vero è che FortiBleed non è più una fuga di dati, ma un canale di accesso pronto all’uso. Oltre 86.000 login Fortinet già verificati come funzionanti vengono ora selezionati per riuso e rivendita: una password valida basta a entrare nei gateway FortiGate e SSL VPN senza dover sfruttare un nuovo bug.
Fortinet attribuisce la campagna al riuso di credenziali e al brute-force contro dispositivi con password deboli e senza MFA; CISA e altri enti parlano di attività in corso contro migliaia di dispositivi esposti su Internet. Le credenziali risultano distribuite in 194 paesi, e il formato della raccolta fa pensare a un uso da eCrime, non a una semplice lista di esposizione.
Per chi gestisce accessi remoti e admin password-based, la falla non è più nel firmware ma nella fiducia accordata a login già compromessi. Se quelle credenziali sono state riutilizzate altrove, il rischio è accesso diretto, session takeover e modifiche amministrative senza toccare il firewall.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet… EPSS 86% (100º percentile).
Data di correzione federale CISA 30 gen · data superata
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: a improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS… EPSS 68% (99º percentile).
Data di correzione federale CISA 23 dic · data superata
NVD KEV
CVSS 9.8 CRITICAL: an improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through… EPSS 29% (98º percentile).
Cronologia Fonti 11 fonti che coprono questa storia
The Hacker News 22 giu
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
This week’s cybersecurity recap covers Firefox and Chrome bugs, EDR-killer tools, a TV botnet, an OpenBSD flaw, Android malware, Splunk exploitation
Cybersecurity Dive 22 giu
CISA urges device hardening after thousands of Fortinet credentials compromised
Security researchers warn of a months-long FortiBleed campaign targeting western organizations.
Industrial Cyber 22 giu
Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls, VPN gateways - Industrial Cyber
Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls and VPN gateways.
SecurityWeek 22 giu
Fortinet Responds to FortiBleed Campaign
A database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign.
Infosecurity Magazine 22 giu
NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout
The NCSC has released guidance for Fortinet customers impacted by the FortiBleed threat campaign
The Hacker News 19 giu
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
FortiBleed attackers compromised 86,644 FortiGate devices using credential attacks, prompting CISA to urge password resets and MFA.
Kevin Beaumont 19 giu
An update on FortiBleed — what’s happening with victim orgs
Attackers on internal networks, password cracked and other Friday fun.
Risky Biz News 19 giu
Risky Bulletin: Creds for 74,000 Fortinet devices leaked
A LOT of Fortinet creds have leaked online, Canada’s spy agency allowed to remove a botnet from Canadian devices, a supply chain attack hi [Read More
SecurityWeek 19 giu
In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover.
SecurityWeek 19 giu
FortiBleed: 86,000 Fortinet Device Credentials Compromised
The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs.
BleepingComputer 19 giu
CISA warns Fortinet users to secure devices after FortiBleed leak
Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed "FortiBleed."
CSIRT Italia / ACN 18 giu
FortiBleed: esposizione di credenziali SSL-VPN associate a dispositivi Fortinet esposti su Internet
Questo CSIRT ha recentemente rilevato la diffusione di un dataset riconducibile a una campagna denominata “FortiBleed”, contenente informazioni associate a dispositivi Fortinet/FortiGate esposti su Internet e utilizzati per l’accesso remoto tramite SSL-VPN.
Entità CVE-2026-24858 CVE-2025-59718 CVE-2025-59719 Riepilogo fornitore: Fortinet
Part of the PlainSec briefing for 2026-06-23
Editions Storie correlate
Vulnerabilità · 99 giorni fa
FortiBleed diventa un magazzino di credenziali operative Il cambio vero è che FortiBleed non è più una fuga di dati, ma un canale di accesso pronto all’uso. Oltre 86.000 login Fortinet già verificati come funzionanti vengono ora selezionati per riuso e rivendita: una password valida basta a entrare nei gateway FortiGate e SSL VPN senza dover sfruttare un nuovo bug.
Fortinet attribuisce la campagna al riuso di credenziali e al brute-force contro dispositivi con password deboli e senza MFA; CISA e altri enti parlano di attività in corso contro migliaia di dispositivi esposti su Internet. Le credenziali risultano distribuite in 194 paesi, e il formato della raccolta fa pensare a un uso da eCrime, non a una semplice lista di esposizione.
Per chi gestisce accessi remoti e admin password-based, la falla non è più nel firmware ma nella fiducia accordata a login già compromessi. Se quelle credenziali sono state riutilizzate altrove, il rischio è accesso diretto, session takeover e modifiche amministrative senza toccare il firewall.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet… EPSS 86% (100º percentile).
Data di correzione federale CISA 30 gen · data superata
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: a improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS… EPSS 68% (99º percentile).
Data di correzione federale CISA 23 dic · data superata
NVD KEV
CVSS 9.8 CRITICAL: an improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through… EPSS 29% (98º percentile).
Cronologia Fonti 11 fonti che coprono questa storia
The Hacker News 22 giu
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
This week’s cybersecurity recap covers Firefox and Chrome bugs, EDR-killer tools, a TV botnet, an OpenBSD flaw, Android malware, Splunk exploitation
Cybersecurity Dive 22 giu
CISA urges device hardening after thousands of Fortinet credentials compromised
Security researchers warn of a months-long FortiBleed campaign targeting western organizations.
Industrial Cyber 22 giu
Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls, VPN gateways - Industrial Cyber
Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls and VPN gateways.
SecurityWeek 22 giu
Fortinet Responds to FortiBleed Campaign
A database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign.
Infosecurity Magazine 22 giu
NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout
The NCSC has released guidance for Fortinet customers impacted by the FortiBleed threat campaign
The Hacker News 19 giu
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
FortiBleed attackers compromised 86,644 FortiGate devices using credential attacks, prompting CISA to urge password resets and MFA.
Kevin Beaumont 19 giu
An update on FortiBleed — what’s happening with victim orgs
Attackers on internal networks, password cracked and other Friday fun.
Risky Biz News 19 giu
Risky Bulletin: Creds for 74,000 Fortinet devices leaked
A LOT of Fortinet creds have leaked online, Canada’s spy agency allowed to remove a botnet from Canadian devices, a supply chain attack hi [Read More
SecurityWeek 19 giu
In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover.
SecurityWeek 19 giu
FortiBleed: 86,000 Fortinet Device Credentials Compromised
The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs.
BleepingComputer 19 giu
CISA warns Fortinet users to secure devices after FortiBleed leak
Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed "FortiBleed."
CSIRT Italia / ACN 18 giu
FortiBleed: esposizione di credenziali SSL-VPN associate a dispositivi Fortinet esposti su Internet
Questo CSIRT ha recentemente rilevato la diffusione di un dataset riconducibile a una campagna denominata “FortiBleed”, contenente informazioni associate a dispositivi Fortinet/FortiGate esposti su Internet e utilizzati per l’accesso remoto tramite SSL-VPN.
Entità CVE-2026-24858 CVE-2025-59718 CVE-2025-59719 Riepilogo fornitore: Fortinet
Part of the PlainSec briefing for 2026-06-23
Editions Storie correlate