Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Thousands of Fortinet Firewalls Targeted in Global Cyber Attack

Thousands of Fortinet Firewalls Targeted in Global Cyber Attack

Posted on June 18, 2026 By CWS

A massive cyber espionage operation, referred to as ‘FortiBleed’, has compromised over 73,932 unique Fortinet firewall URLs worldwide. This extensive attack spans 194 countries, illustrating the scale and reach of the operation. The breach was initially identified by security researcher Volodymyr ‘Bob’ Diachenko and further analyzed by Hudson Rock, revealing an industrial-scale targeting of FortiGate devices and SSL VPN gateways.

Details of the FortiBleed Campaign

The attackers executed approximately 1.16 billion credential-based attempts against more than 320,000 FortiGate targets. In addition, over 2.1 billion brute-force attempts were launched against 160,000 MSSQL servers, leading to the compromise of 21,632 unique domains. These attacks are attributed to a Russian-speaking cybercriminal group, employing sophisticated methods beyond simple credential stuffing.

The group systematically scanned the internet for exposed Fortinet instances, testing them against vast databases of historical credential leaks collected by infostealer malware. Once access was gained, attackers could infiltrate internal Active Directory environments, maintaining persistent network access despite standard security measures.

Technical Vectors and Global Impact

A key aspect of the campaign was the interception of SSL VPN authentication hashes, which were cracked offline using a powerful GPU cluster managed through Hashtopolis. This method exposed organizations’ encrypted credentials, allowing attackers to continuously harvest additional logins. The breach affected numerous sectors, including technology, manufacturing, professional services, telecommunications, and government entities worldwide.

Notably, organizations in Japan, Taiwan, Vietnam, Iraq, and Turkey were compromised, including a Turkish NATO defense contractor from which classified documents were stolen. The attackers accumulated a database of credentials from major enterprises, highlighting the ineffectiveness of complex passwords when credentials are compromised at the endpoint level.

Mitigation Steps for Organizations

Given the severity of the FortiBleed campaign, organizations using Fortinet devices must take immediate action. It is crucial to reset all Fortinet VPN and admin passwords, regardless of their complexity, as they may have been compromised. Implementing Multi-Factor Authentication (MFA) across all external gateways is also essential in neutralizing stolen credentials.

Additionally, organizations should audit Fortinet access logs for any irregularities, such as unexpected login locations or unusual traffic volumes. Restricting management interface exposure to trusted internal IPs and disabling unnecessary FortiCloud SSO accounts is also recommended to enhance security.

The FortiBleed attack underscores the vulnerability of perimeter security, especially in an era where infostealer-harvested data is prevalent. Organizations must adopt robust security measures to protect against future threats and safeguard sensitive information.

Cyber Security News Tags:Active Directory, credential theft, cyber attack, Cybersecurity, firewall breach, Fortinet, InfoStealer, multi-factor authentication, network security, SSL-VPN

Post navigation

Previous Post: Hackers Exploit ClickFix to Deploy Remote Access Tools
Next Post: Microsoft Addresses Critical Defender Vulnerability

Related Posts

BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service Cyber Security News
Predator Mobile Spyware Remains Consistent with New Design Changes to Evade Detection Predator Mobile Spyware Remains Consistent with New Design Changes to Evade Detection Cyber Security News
How Fiber Optic Cables Can Secretly Eavesdrop on Conversations How Fiber Optic Cables Can Secretly Eavesdrop on Conversations Cyber Security News
Access to Anthropic AI Models Restricted by U.S. Government Access to Anthropic AI Models Restricted by U.S. Government Cyber Security News
Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System Cyber Security News
Microsoft 365 PDF Export LFI Vulnerability Allows Access to Sensitive Server Data Microsoft 365 PDF Export LFI Vulnerability Allows Access to Sensitive Server Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome 153 Update Addresses Critical Security Flaws
  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome 153 Update Addresses Critical Security Flaws
  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark