Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Addresses FortiBleed Threat to Firewalls

Fortinet Addresses FortiBleed Threat to Firewalls

Posted on June 22, 2026 By CWS

Fortinet has issued a response regarding a large-scale credential-harvesting threat known as the FortiBleed campaign, which is currently impacting its firewalls and VPNs globally. The cybersecurity firm clarified that the campaign does not stem from any newly discovered vulnerabilities in its systems.

Understanding the FortiBleed Campaign

The FortiBleed operation has compiled an extensive database containing over 86,000 verified credentials from Fortinet devices in 194 nations. According to Fortinet, the attack involves reusing credentials from previous breaches and utilizing brute-force methods on systems with weak passwords and lacking multi-factor authentication (MFA).

These previous breaches exploited specific FortiCloud SSO login flaws, namely CVE-2026-24858, patched earlier this year, and CVE-2025-59718 and CVE-2025-59719, addressed last December. Fortinet had provided guidance on these issues and continues to urge customers to follow these remediation steps.

Impact and Guidance for Fortinet Users

In March, Fortinet had highlighted the use of AI by threat actors to automate the identification of targets and execute password spraying attacks against inadequately secured edge devices. The FortiBleed campaign employs similar tactics, yet it is not tied to any new vulnerabilities in Fortinet’s products.

Fortinet has taken action by identifying potentially compromised systems, notifying affected customers, and collaborating with law enforcement for an in-depth investigation. Customers with compromised FortiGate devices are advised to take specific security measures to safeguard their systems.

Recommended Security Measures

To protect against this threat, customers should end active admin and VPN sessions, refresh their credentials, enable MFA for all admin and VPN accounts, and upgrade to the latest software that supports PBKDF2 hashing for securing admin credentials. Additionally, reviewing firewall and VPN configurations for unauthorized changes is crucial.

Monitoring logs for unusual admin access and limiting external management to trusted hosts can further minimize the risk of attack. Implementing these strategies is essential for maintaining the security and integrity of network systems against ongoing threats.

Related topics include the implications of the CryptoBandits malware, which functions as a backdoor while exploiting Tor, and recent vulnerabilities patched in Fortinet and Ivanti products.

Security Week News Tags:credential harvesting, Cybersecurity, Firewalls, FortiBleed, Fortinet, multi-factor authentication, Security, Threat Actors, VPN, Vulnerabilities

Post navigation

Previous Post: Squid Proxy Vulnerability ‘Squidbleed’ Exposes HTTP Requests
Next Post: Critical Squid Proxy Vulnerability Exposed with AI Assistance

Related Posts

Why We Can’t Let AI Take the Wheel of Cyber Defense Why We Can’t Let AI Take the Wheel of Cyber Defense Security Week News
574 Arrested,  Million Seized in Crackdown on African Cybercrime Rings 574 Arrested, $3 Million Seized in Crackdown on African Cybercrime Rings Security Week News
Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements Security Week News
VMScape: Academics Break Cloud Isolation With New Spectre Attack VMScape: Academics Break Cloud Isolation With New Spectre Attack Security Week News
700,000 Records Compromised in Askul Ransomware Attack 700,000 Records Compromised in Askul Ransomware Attack Security Week News
Data Breach at Conduent Exposes Volvo Group Employees Data Breach at Conduent Exposes Volvo Group Employees Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical WordPress Vulnerability Allows Remote Code Execution
  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
  • Malware Exploits Windows Hello Keys for Entra ID Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical WordPress Vulnerability Allows Remote Code Execution
  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
  • Malware Exploits Windows Hello Keys for Entra ID Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark