Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Urges Fortinet Users to Secure Devices Amid Attack

CISA Urges Fortinet Users to Secure Devices Amid Attack

Posted on June 19, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to users of Fortinet’s FortiGate devices, urging them to enhance their security measures against an active threat campaign. This advisory comes in response to the discovery of a large-scale cyberattack named FortiBleed, which has compromised 86,644 devices as of June 19, 2026.

The FortiBleed Campaign: An Overview

Attributed to a group of Russian-speaking hackers, FortiBleed has primarily targeted Fortinet systems through internet-exposed devices. Data from SOCRadar indicates a significant portion of compromised credentials are generic admin accounts (35%) and built-in Fortinet system accounts (28.3%). Organization-specific credentials account for the remaining 36.7%, suggesting a widespread failure to update default settings, providing attackers with easy targets.

These compromised credentials highlight the importance of changing default account names and regularly rotating passwords. A notable proportion of affected accounts were organization-specific, which implies that attackers have not only targeted default credentials but have also exploited accounts created by the institutions themselves, possibly from past breaches where credentials were not updated.

Targeted Industries and Attack Methodology

The most affected sectors include telecommunications, government, and education, with significant impacts observed in countries such as India, the United States, Mexico, Colombia, and Thailand. The attackers are known to have conducted mass scans for Fortinet remote login endpoints, using a custom-built tool to attempt entry with known password combinations.

This sophisticated attack is automated and follows a two-step method. Initially, attackers try a list of leaked Fortinet passwords on devices globally. If access is gained, they then quietly observe network traffic to gather more credentials, further extending their reach by compromising additional devices.

Preventive Measures and Recommendations

In light of this breach, the U.K. National Cyber Security Centre (NCSC) has classified FortiBleed as a worldwide campaign against Fortinet firewalls and VPN gateways, employing tactics such as brute-force and credential stuffing. It is suspected that the attackers exploited older credential hashing methods used in FortiGate configurations.

Fortinet has recently updated its systems to use PBKDF2-based password hashing, replacing the older SHA-256 mechanism. However, many systems still operate with outdated credentials, leaving them vulnerable. Fortinet advises organizations to adhere to best practices, including regular password rotations and enabling multi-factor authentication.

To counteract these threats, CISA has provided several recommendations: terminate active SSL VPN and administrative sessions, reset passwords on internet-facing systems, enforce robust password policies, and utilize the PBKDF2 algorithm for storing credentials. Monitoring logs for unauthorized activity and enabling phishing-resistant multi-factor authentication are also crucial steps.

This incident was initially uncovered by security researcher Volodymyr Diachenko, who found a server containing thousands of login credentials for firewalls and VPNs across 194 countries. The server also hosted the attackers’ tools and scripts, illustrating the potential for credential reuse and poor password hygiene to be exploited by cybercriminals.

The FortiBleed attack underscores the critical need for rigorous cybersecurity measures and highlights the ongoing risk perimeter devices pose as entry points for attackers.

The Hacker News Tags:admin accounts, CISA, credential breach, Cybersecurity, Firewall, FortiBleed, Fortinet, global campaign, multi-factor authentication, network security, password hygiene, password protection, security protocols, threat intelligence, VPN security

Post navigation

Previous Post: eFAQ Exposes Coordinated Online Reputation Attack
Next Post: Critical Flaws in Chrome Extensions Risk Millions

Related Posts

Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC The Hacker News
New Exploit Targets Patched vBulletin Code Flaw New Exploit Targets Patched vBulletin Code Flaw The Hacker News
Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine The Hacker News
Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access The Hacker News
Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances The Hacker News
Earth Ammit Breached Drone Supply Chains via ERP in VENOM, TIDRONE Campaigns Earth Ammit Breached Drone Supply Chains via ERP in VENOM, TIDRONE Campaigns The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in Check Point Systems Requires Immediate Patching
  • Telegram Briefly Removed from Apple App Store Due to Guidelines
  • Microsoft Awards $20 Million in Bug Bounties
  • New York Allocates $9 Million for Water System Cybersecurity
  • Android RAT Threat Poses as Emergency App

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in Check Point Systems Requires Immediate Patching
  • Telegram Briefly Removed from Apple App Store Due to Guidelines
  • Microsoft Awards $20 Million in Bug Bounties
  • New York Allocates $9 Million for Water System Cybersecurity
  • Android RAT Threat Poses as Emergency App

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark