Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Devices Targeted by FortiBleed Attackers

Fortinet Devices Targeted by FortiBleed Attackers

Posted on October 8, 2026 By CWS

The ongoing FortiBleed campaign is posing significant threats to organizations by targeting Fortinet devices, notably locking users out. This campaign, which started in June, focuses on Fortinet FortiGate firewalls and SSL VPN appliances accessible via the internet. The attackers are utilizing compromised credentials and brute-force methods to gain control over inadequately secured devices.

Widespread Impact Across Countries

In a matter of days, this attack reached over 86,000 Fortinet devices across 190 nations. SOCRadar has verified that approximately 86,644 devices in 194 countries have been compromised. The attackers are actively seeking out exposed firewalls, using acquired credentials to take control of these devices, significantly affecting global cybersecurity.

The campaign is attributed to a Russian initial access broker, who is leveraging previously stolen credentials to breach devices. Moreover, a joint advisory by the FBI and the US Secret Service warns of the attackers’ tactics, which include changing passwords and deleting user accounts to lock out legitimate users.

Technical Details of the Attack

The attackers have been observed scanning for SSL VPN portals, extracting credentials from infostealer logs, and breaking hashed credentials offline. They expertly map out attack surfaces to avoid detection and use verified credentials to compromise devices. Additionally, they sell VPN configurations and target lists to other cybercriminals, exacerbating the threat.

The advisory highlights the importance of recognizing compromised devices, assessing the extent of intrusions, and evicting attackers to prevent further damage. Strengthening security measures is crucial to thwarting these threats and maintaining network integrity.

Recommendations for Organizations

The FBI and US Secret Service recommend several steps to mitigate these attacks. Organizations should restrict management access, reset all VPN and administrative passwords, and adopt phishing-resistant multifactor authentication. Reviewing firewall and VPN configurations and securing API keys are also advised to reduce vulnerabilities.

Furthermore, companies should analyze logs for any suspicious activity and ensure that credential storage is secure. Such proactive measures are vital for defending against the evolving tactics of cyber attackers.

Related topics include the long-running NPM malware campaign, Anthropic’s cyber verification program for AI access, and Wikimedia’s challenges with rogue OpenAI agents.

Security Week News Tags:access broker, credential compromise, credential harvesting, Cyberattack, Cybersecurity, device security, FBI, FortiBleed, Fortigate, Fortinet, network security, Phishing, SOCRadar, US Secret Service, VPN

Post navigation

Previous Post: Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities
Next Post: VirusTotal API Keys Allegedly Sold on Dark Web

Related Posts

TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks Security Week News
Windows’ Infamous ‘Blue Screen of Death’ Will Soon Turn Black Windows’ Infamous ‘Blue Screen of Death’ Will Soon Turn Black Security Week News
European Commission Confirms Cyberattack on Cloud Systems European Commission Confirms Cyberattack on Cloud Systems Security Week News
Masimo Manufacturing Facilities Hit by Cyberattack Masimo Manufacturing Facilities Hit by Cyberattack Security Week News
Security Flaw Exposes OpenAI Code via AI-Generated Exploit Security Flaw Exposes OpenAI Code via AI-Generated Exploit Security Week News
Organizations Warned of Exploited Sudo Vulnerability Organizations Warned of Exploited Sudo Vulnerability Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Tensorlake npm Package Exploited to Spread Malware
  • Chinese Hackers Exploited Flaws for Email Theft: FBI
  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Tensorlake npm Package Exploited to Spread Malware
  • Chinese Hackers Exploited Flaws for Email Theft: FBI
  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark