Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Thousands of Fortinet Firewalls Targeted in Global Cyber Attack

Thousands of Fortinet Firewalls Targeted in Global Cyber Attack

Posted on June 18, 2026 By CWS

A massive cyber espionage operation, referred to as ‘FortiBleed’, has compromised over 73,932 unique Fortinet firewall URLs worldwide. This extensive attack spans 194 countries, illustrating the scale and reach of the operation. The breach was initially identified by security researcher Volodymyr ‘Bob’ Diachenko and further analyzed by Hudson Rock, revealing an industrial-scale targeting of FortiGate devices and SSL VPN gateways.

Details of the FortiBleed Campaign

The attackers executed approximately 1.16 billion credential-based attempts against more than 320,000 FortiGate targets. In addition, over 2.1 billion brute-force attempts were launched against 160,000 MSSQL servers, leading to the compromise of 21,632 unique domains. These attacks are attributed to a Russian-speaking cybercriminal group, employing sophisticated methods beyond simple credential stuffing.

The group systematically scanned the internet for exposed Fortinet instances, testing them against vast databases of historical credential leaks collected by infostealer malware. Once access was gained, attackers could infiltrate internal Active Directory environments, maintaining persistent network access despite standard security measures.

Technical Vectors and Global Impact

A key aspect of the campaign was the interception of SSL VPN authentication hashes, which were cracked offline using a powerful GPU cluster managed through Hashtopolis. This method exposed organizations’ encrypted credentials, allowing attackers to continuously harvest additional logins. The breach affected numerous sectors, including technology, manufacturing, professional services, telecommunications, and government entities worldwide.

Notably, organizations in Japan, Taiwan, Vietnam, Iraq, and Turkey were compromised, including a Turkish NATO defense contractor from which classified documents were stolen. The attackers accumulated a database of credentials from major enterprises, highlighting the ineffectiveness of complex passwords when credentials are compromised at the endpoint level.

Mitigation Steps for Organizations

Given the severity of the FortiBleed campaign, organizations using Fortinet devices must take immediate action. It is crucial to reset all Fortinet VPN and admin passwords, regardless of their complexity, as they may have been compromised. Implementing Multi-Factor Authentication (MFA) across all external gateways is also essential in neutralizing stolen credentials.

Additionally, organizations should audit Fortinet access logs for any irregularities, such as unexpected login locations or unusual traffic volumes. Restricting management interface exposure to trusted internal IPs and disabling unnecessary FortiCloud SSO accounts is also recommended to enhance security.

The FortiBleed attack underscores the vulnerability of perimeter security, especially in an era where infostealer-harvested data is prevalent. Organizations must adopt robust security measures to protect against future threats and safeguard sensitive information.

Cyber Security News Tags:Active Directory, credential theft, cyber attack, Cybersecurity, firewall breach, Fortinet, InfoStealer, multi-factor authentication, network security, SSL-VPN

Post navigation

Previous Post: Hackers Exploit ClickFix to Deploy Remote Access Tools

Related Posts

Critical SolarWinds Vulnerability Exposes 170 Installations Critical SolarWinds Vulnerability Exposes 170 Installations Cyber Security News
CISA Expands KEV Catalog with 1,484 New Vulnerabilities as Active Exploitation Surges 20% in 2025 CISA Expands KEV Catalog with 1,484 New Vulnerabilities as Active Exploitation Surges 20% in 2025 Cyber Security News
G_Wagon npm Package Attacking Users to Exfiltrates Browser Credentials using Obfuscated Payload G_Wagon npm Package Attacking Users to Exfiltrates Browser Credentials using Obfuscated Payload Cyber Security News
Threat Actors Employ Clickfix Tactics to Deliver Malicious AppleScripts That Steal Login Credentials Threat Actors Employ Clickfix Tactics to Deliver Malicious AppleScripts That Steal Login Credentials Cyber Security News
PyPI Package Compromised by Malicious Scripts PyPI Package Compromised by Malicious Scripts Cyber Security News
Chinese Hackers Weaponized Nezha Tool to Execute Commands on Web Server Chinese Hackers Weaponized Nezha Tool to Execute Commands on Web Server Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Thousands of Fortinet Firewalls Targeted in Global Cyber Attack
  • Hackers Exploit ClickFix to Deploy Remote Access Tools
  • OpenBSD Vulnerability Bypasses PAP Authentication
  • Optimizing URL Phishing Triage with Browser Insights
  • AI-Driven Phishing Threats Rise, SpyCloud Reports

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Thousands of Fortinet Firewalls Targeted in Global Cyber Attack
  • Hackers Exploit ClickFix to Deploy Remote Access Tools
  • OpenBSD Vulnerability Bypasses PAP Authentication
  • Optimizing URL Phishing Triage with Browser Insights
  • AI-Driven Phishing Threats Rise, SpyCloud Reports

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark