Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FortiBleed Campaign Compromises 86,000 Fortinet Devices

FortiBleed Campaign Compromises 86,000 Fortinet Devices

Posted on June 19, 2026 By CWS

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to organizations to strengthen their Fortinet devices that are accessible via the internet. This follows a credential theft campaign, known as FortiBleed, which is estimated to have affected more than 86,000 firewalls and VPNs worldwide.

FortiBleed Campaign Unveiled

The FortiBleed campaign was identified earlier this week, initially flagged by SOCRadar. The security platform first estimated that over 30,000 Fortinet devices had been compromised, but that number has since increased to 86,000. The operation, uncovered in June 2026, has resulted in the assembly of a validated database containing over 86,644 working credentials from 194 countries, all extracted from Fortinet’s online infrastructure.

Attackers have amassed a collection of usernames and passwords, which have been tested using automated tools. Some of these credentials may have been exposed in earlier breaches but remained unchanged and therefore vulnerable.

Collaborative Verification Efforts

Security experts Kevin Beaumont and Hudson Rock have collaborated with some affected entities to validate the authenticity and currency of the compromised logins. Beaumont indicates that about half of all Fortinet firewalls accessible on the internet have been impacted, as per data from Shodan.

Bob Diachenko, another security researcher, attributes the orchestrated campaign to a Russian-speaking threat group. This operation has completely compromised at least four organizations by intercepting SSL VPN authentication, using a powerful 45-GPU cluster managed through Hashtopolis to crack password hashes, and infiltrating internal Active Directory systems.

Widespread Impact and Protective Measures

The scale of this attack is significant, with approximately 1.16 billion credential attempts directed at over 320,000 FortiGate targets and 2.1 billion brute-force attempts targeting more than 160,000 MSSQL servers. Hudson Rock reports that this campaign has impacted thousands of organizations, including vital government agencies and key infrastructure providers.

Cybersecurity firm Huntress also confirmed the widespread nature of the FortiBleed campaign, identifying 845 partner organizations specifically affected by the credential exposure. In response, CISA has advised Fortinet users to take several protective actions. These include ending active sessions, resetting credentials, employing the Password-Based Key Derivation Function 2 (PBKDF2) for storing admin passwords, scrutinizing logs for unusual activities, enabling phishing-resistant multi-factor authentication (MFA), and restricting management access to minimize the potential attack surface.

The cybersecurity landscape continues to be shaped by large-scale data breaches and credential thefts, highlighting the need for persistent vigilance and advanced security protocols to safeguard organizational assets.

Security Week News Tags:CISA, credential theft, cyber attack, Cybersecurity, data breach, enterprise networks, firewall security, FortiBleed, Fortinet, internet security, MFA, password security, Russia, Shodan, VPN security

Post navigation

Previous Post: Node.js Security Update Addresses Critical Vulnerabilities
Next Post: Sophisticated Crypto Clipper Malware Targets USB Drives

Related Posts

Google Revamps Bug Bounties as AI Transforms Security Google Revamps Bug Bounties as AI Transforms Security Security Week News
CMMC Live: Pentagon Demands Verified Cybersecurity From Contractors CMMC Live: Pentagon Demands Verified Cybersecurity From Contractors Security Week News
Over 6,700 Private Repositories Made Public in Nx Supply Chain Attack Over 6,700 Private Repositories Made Public in Nx Supply Chain Attack Security Week News
Russian Hackers Exploited WinRAR Zero-Day in Attacks on Europe, Canada Russian Hackers Exploited WinRAR Zero-Day in Attacks on Europe, Canada Security Week News
Gmail Introduces Enhanced Email Encryption for Business Users Gmail Introduces Enhanced Email Encryption for Business Users Security Week News
Personal Information Compromised in Freedom Mobile Data Breach Personal Information Compromised in Freedom Mobile Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI’s Role in Transforming Threat Management Strategies
  • E-commerce Sites Targeted by Malware Through Okendo Widget
  • CryptoBandits Malware Abuses Tor for RCE and Data Theft
  • Access Control: The New Challenge of Shadow AI
  • Sophisticated Crypto Clipper Malware Targets USB Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI’s Role in Transforming Threat Management Strategies
  • E-commerce Sites Targeted by Malware Through Okendo Widget
  • CryptoBandits Malware Abuses Tor for RCE and Data Theft
  • Access Control: The New Challenge of Shadow AI
  • Sophisticated Crypto Clipper Malware Targets USB Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark