Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Urges Fortinet Users to Secure Devices Amid Attack

CISA Urges Fortinet Users to Secure Devices Amid Attack

Posted on June 19, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to users of Fortinet’s FortiGate devices, urging them to enhance their security measures against an active threat campaign. This advisory comes in response to the discovery of a large-scale cyberattack named FortiBleed, which has compromised 86,644 devices as of June 19, 2026.

The FortiBleed Campaign: An Overview

Attributed to a group of Russian-speaking hackers, FortiBleed has primarily targeted Fortinet systems through internet-exposed devices. Data from SOCRadar indicates a significant portion of compromised credentials are generic admin accounts (35%) and built-in Fortinet system accounts (28.3%). Organization-specific credentials account for the remaining 36.7%, suggesting a widespread failure to update default settings, providing attackers with easy targets.

These compromised credentials highlight the importance of changing default account names and regularly rotating passwords. A notable proportion of affected accounts were organization-specific, which implies that attackers have not only targeted default credentials but have also exploited accounts created by the institutions themselves, possibly from past breaches where credentials were not updated.

Targeted Industries and Attack Methodology

The most affected sectors include telecommunications, government, and education, with significant impacts observed in countries such as India, the United States, Mexico, Colombia, and Thailand. The attackers are known to have conducted mass scans for Fortinet remote login endpoints, using a custom-built tool to attempt entry with known password combinations.

This sophisticated attack is automated and follows a two-step method. Initially, attackers try a list of leaked Fortinet passwords on devices globally. If access is gained, they then quietly observe network traffic to gather more credentials, further extending their reach by compromising additional devices.

Preventive Measures and Recommendations

In light of this breach, the U.K. National Cyber Security Centre (NCSC) has classified FortiBleed as a worldwide campaign against Fortinet firewalls and VPN gateways, employing tactics such as brute-force and credential stuffing. It is suspected that the attackers exploited older credential hashing methods used in FortiGate configurations.

Fortinet has recently updated its systems to use PBKDF2-based password hashing, replacing the older SHA-256 mechanism. However, many systems still operate with outdated credentials, leaving them vulnerable. Fortinet advises organizations to adhere to best practices, including regular password rotations and enabling multi-factor authentication.

To counteract these threats, CISA has provided several recommendations: terminate active SSL VPN and administrative sessions, reset passwords on internet-facing systems, enforce robust password policies, and utilize the PBKDF2 algorithm for storing credentials. Monitoring logs for unauthorized activity and enabling phishing-resistant multi-factor authentication are also crucial steps.

This incident was initially uncovered by security researcher Volodymyr Diachenko, who found a server containing thousands of login credentials for firewalls and VPNs across 194 countries. The server also hosted the attackers’ tools and scripts, illustrating the potential for credential reuse and poor password hygiene to be exploited by cybercriminals.

The FortiBleed attack underscores the critical need for rigorous cybersecurity measures and highlights the ongoing risk perimeter devices pose as entry points for attackers.

The Hacker News Tags:admin accounts, CISA, credential breach, Cybersecurity, Firewall, FortiBleed, Fortinet, global campaign, multi-factor authentication, network security, password hygiene, password protection, security protocols, threat intelligence, VPN security

Post navigation

Previous Post: eFAQ Exposes Coordinated Online Reputation Attack
Next Post: Critical Flaws in Chrome Extensions Risk Millions

Related Posts

Hard-Coded Credentials Found in HPE Instant On Devices Allow Admin Access Hard-Coded Credentials Found in HPE Instant On Devices Allow Admin Access The Hacker News
Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet The Hacker News
Experts Detect Multi-Layer Redirect Tactic Used to Steal Microsoft 365 Login Credentials Experts Detect Multi-Layer Redirect Tactic Used to Steal Microsoft 365 Login Credentials The Hacker News
UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud The Hacker News
Dangerous npm Package Steals macOS Credentials Dangerous npm Package Steals macOS Credentials The Hacker News
ShareFile Users Advised to Shut Down Controllers Amid Security Alert ShareFile Users Advised to Shut Down Controllers Amid Security Alert The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark