Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Urges Fortinet Device Security Amid FortiBleed Threat

CISA Urges Fortinet Device Security Amid FortiBleed Threat

Posted on June 19, 2026 By CWS

The Cybersecurity and Infrastructure Security Agency (CISA) has released a critical advisory urging organizations to enhance the security of their Fortinet devices following the revelation of a significant credential exposure incident, known as the “FortiBleed” attack.

Global Impact of FortiBleed Campaign

This alert follows the discovery of malicious actors exploiting compromised credentials across a vast number of Fortinet systems, with tens of thousands of internet-facing devices being affected worldwide. According to CISA, the breach involves leaked credentials linked to about 74,000 Fortinet devices, including FortiGate firewalls and SSL VPN gateways.

The incident has impacted both government and private-sector entities across various regions, sparking serious concerns over unauthorized access and the potential for lateral movement within networks.

Security Firms Highlight Global Scope

Security firms such as SOCRadar, Hudson Rock, and Arctic Wolf have noted that the attack spans over 190 countries, underscoring its global reach. Many compromised devices were directly accessible online, making them prime targets for attackers seeking initial network access.

The primary threat arises from the use of valid yet compromised credentials, allowing attackers to circumvent traditional security measures. Once infiltrated, these perpetrators can elevate their access, navigate networks, and potentially install malware or steal sensitive information.

Recommended Security Measures

In response, CISA has strongly advised organizations using Fortinet products to enact immediate defensive strategies. Key actions include terminating active SSL VPN and administrative sessions, resetting all Fortinet-related passwords, and enforcing robust password policies. Ensuring secure credential storage is also critical.

CISA suggests protecting administrator credentials with the Password-Based Key Derivation Function 2 (PBKDF2), a more secure hashing algorithm. Organizations are advised to eliminate older, less secure hashing methods in line with Fortinet’s latest guidance.

Additionally, a thorough review of logs is recommended to identify any signs of compromise. This includes monitoring firewall logs, VPN access records, authentication logs, and domain controller activity for unusual behavior such as unexpected login attempts, unauthorized account creation, and configuration changes.

Strengthening Network Defenses

To bolster defenses, enabling phishing-resistant multi-factor authentication (MFA) across all remote access points and administrative interfaces is advised. This step adds an extra layer of security, even if credentials have been leaked.

Reducing the attack surface is also crucial. Administrators should ensure that Fortinet management interfaces are not exposed to the public internet, limiting access to trusted internal networks and promptly removing unauthorized accounts.

The FortiBleed incident highlights the increasing risk of credential-based attacks, with attackers leveraging stolen login details over software vulnerabilities. It emphasizes the necessity of proactive security measures such as strong authentication practices, effective credential management, and continuous monitoring.

Although no specific CVE has been linked to this campaign, the wide-reaching impact of the breach demonstrates how misconfigurations and credential leaks can create substantial security vulnerabilities. Organizations are urged to review CISA’s guidance and relevant threat intelligence reports to evaluate their exposure and take swift action.

Cyber Security News Tags:CISA, credential exposure, Cybersecurity, FortiBleed, Fortinet, multi-factor authentication, network security, password security, SSL-VPN, threat intelligence

Post navigation

Previous Post: Gentlemen RaaS Targets Security with EDR Framework

Related Posts

North Korean Cybercriminals Intensify Crypto Attacks North Korean Cybercriminals Intensify Crypto Attacks Cyber Security News
Threat Actors Leveraging RMM Tools to Attack Users via Weaponized PDF Files Threat Actors Leveraging RMM Tools to Attack Users via Weaponized PDF Files Cyber Security News
APT Groups Attacking Construction Industry Networks to Steal RDP, SSH and Citrix Logins APT Groups Attacking Construction Industry Networks to Steal RDP, SSH and Citrix Logins Cyber Security News
Microsoft Teams Enhances Security by Removing EXIF Data Microsoft Teams Enhances Security by Removing EXIF Data Cyber Security News
New Report Warns of 68% Of Actively Serving Phishing Kits Protected by CloudFlare New Report Warns of 68% Of Actively Serving Phishing Kits Protected by CloudFlare Cyber Security News
20+ Malicious Apps on Google Play Actively Attacking Users to Steal Login Credentials 20+ Malicious Apps on Google Play Actively Attacking Users to Steal Login Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework
  • Rust-Based Ransomware Threatens Global Industries
  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework
  • Rust-Based Ransomware Threatens Global Industries
  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark