FortiBleed Vulnerability: Attackers Exploit Fortinet Firewalls to Lock Out Admins

www.news4hackers.com-fortibleed-vulnerability-attackers-exploit-fortinet-firewalls-to-lock-out-admins-fortibleed-vulnerability-attackers-exploit-fortinet-firewalls-to-lock-out-admins

FortiBleed remains active, with threat actors exploiting vulnerabilities in Fortinet firewalls to prevent administrators from accessing critical systems.

FortiBleed Threat Overview

FortiBleed remains active, with threat actors exploiting vulnerabilities in Fortinet firewalls to prevent administrators from accessing critical systems. A joint advisory from the FBI and U.S. Secret Service highlights that some organizations have been locked out of their Fortinet FortiGate firewalls and SSL VPN gateways due to the ongoing FortiBleed campaign.

Joint Advisory from FBI and U.S. Secret Service

The advisory, which references findings from SOCRadar, confirms that over 86,644 devices across 194 countries have been compromised. Attackers target internet-facing Fortinet infrastructure, leveraging initial access to manipulate user accounts.

In certain cases, threat actors delete or alter existing administrative credentials, effectively blocking organizations from regaining control of affected systems.

Attack Methods and Persistent Access

The malicious actors also establish persistent access by creating new user accounts not previously present on the devices. This dual approach ensures continued control while enabling lateral movement within compromised networks.

Recovery Challenges

Recovery efforts for impacted entities extend beyond standard patching and password resets. The advisory warns that attackers are actively scanning exposed Fortinet firewalls using credentials obtained from prior breaches.

Credential Stuffing and Password Spraying

These credentials are derived from leaked data and infostealer logs, which are then used in credential stuffing and password spraying campaigns. Attackers extract password hashes from compromised systems and crack them using GPU clusters equipped with tools like Hashcat and Hashtopolis.

Reconnaissance and Ransomware Linkages

Once credentials are validated, attackers perform reconnaissance to identify privileged accounts within Active Directory. This phase includes mapping organizational structures and prioritizing targets based on financial value and network complexity. The compromised access is subsequently sold to affiliates linked to the INC/Lynx and Payload ransomware groups.

Mitigation Strategies and Warnings

The FBI and Secret Service have identified specific IP addresses and usernames associated with the attacks, alongside recommended mitigation strategies. While reporting incidents is voluntary, the agencies urge affected organizations to disclose breaches and advise against paying ransom demands.

Evolving Threat Landscape

The advisory underscores the evolving tactics of threat actors, emphasizing the need for continuous monitoring and proactive security measures to counteract persistent threats targeting critical infrastructure.



About Author

en_USEnglish