Vulnerabilities · 88 days ago
Fortinet exposure is no longer just about scanning the perimeter. NCSC says a threat actor leaked a credential database after brute-force, dictionary, and credential-stuffing attempts against internet-facing FortiGate and VPN portals, so reused passwords can still hand out access after the device itself is checked.
The advisory follows global targeting of Fortinet firewalls and VPN gateways, with some potential impact in the UK. NCSC says organisations should investigate affected Fortinet edge devices, and it specifically calls out SSL VPN users because the login portal itself can become the entry point when the same username and password work elsewhere.
That shifts the problem from one appliance to account-level perimeter compromise. A cleaned device does not help if stolen credentials still open VPN or admin access and let attackers back into the network.
2 sources covering this story
Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
An alleged Russian-speaking group of cybercriminals is reportedly compromising and targeting several major companies that use Fortinet Firewalls and VPNs through previously known passwords.
Part of the PlainSec briefing for 2026-06-19