FortiBleed has moved from exposure to reuse. The real break is a confirmed set of more than 86,000 working Fortinet logins that can be reused, sold, or pointed at specific targets, so patching the original flaws does not undo access already harvested.
Fortinet says the campaign is driven by reused credentials and brute-force attacks against weak password hygiene and no MFA, not a new Fortinet bug. The credentials cover FortiGate and SSL VPN environments in 194 countries, and the leak is now being formatted like eCrime inventory instead of a one-off dump.
That changes the threat from a leak around a vendor to direct entry into any network that still trusts a reused FortiGate or VPN password. The forward risk is focused intrusion, session abuse, and admin changes through working credentials that remain valid after the original issue is closed.
CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet… EPSS 86% (100th percentile).
CISA federal remediation date Jan 30 · date passed
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover.
Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed "FortiBleed."
Questo CSIRT ha recentemente rilevato la diffusione di un dataset riconducibile a una campagna denominata “FortiBleed”, contenente informazioni associate a dispositivi Fortinet/FortiGate esposti su Internet e utilizzati per l’accesso remoto tramite SSL-VPN.