Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Urges Fortinet Users to Secure Devices Amid Attack

CISA Urges Fortinet Users to Secure Devices Amid Attack

Posted on June 19, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to users of Fortinet’s FortiGate devices, urging them to enhance their security measures against an active threat campaign. This advisory comes in response to the discovery of a large-scale cyberattack named FortiBleed, which has compromised 86,644 devices as of June 19, 2026.

The FortiBleed Campaign: An Overview

Attributed to a group of Russian-speaking hackers, FortiBleed has primarily targeted Fortinet systems through internet-exposed devices. Data from SOCRadar indicates a significant portion of compromised credentials are generic admin accounts (35%) and built-in Fortinet system accounts (28.3%). Organization-specific credentials account for the remaining 36.7%, suggesting a widespread failure to update default settings, providing attackers with easy targets.

These compromised credentials highlight the importance of changing default account names and regularly rotating passwords. A notable proportion of affected accounts were organization-specific, which implies that attackers have not only targeted default credentials but have also exploited accounts created by the institutions themselves, possibly from past breaches where credentials were not updated.

Targeted Industries and Attack Methodology

The most affected sectors include telecommunications, government, and education, with significant impacts observed in countries such as India, the United States, Mexico, Colombia, and Thailand. The attackers are known to have conducted mass scans for Fortinet remote login endpoints, using a custom-built tool to attempt entry with known password combinations.

This sophisticated attack is automated and follows a two-step method. Initially, attackers try a list of leaked Fortinet passwords on devices globally. If access is gained, they then quietly observe network traffic to gather more credentials, further extending their reach by compromising additional devices.

Preventive Measures and Recommendations

In light of this breach, the U.K. National Cyber Security Centre (NCSC) has classified FortiBleed as a worldwide campaign against Fortinet firewalls and VPN gateways, employing tactics such as brute-force and credential stuffing. It is suspected that the attackers exploited older credential hashing methods used in FortiGate configurations.

Fortinet has recently updated its systems to use PBKDF2-based password hashing, replacing the older SHA-256 mechanism. However, many systems still operate with outdated credentials, leaving them vulnerable. Fortinet advises organizations to adhere to best practices, including regular password rotations and enabling multi-factor authentication.

To counteract these threats, CISA has provided several recommendations: terminate active SSL VPN and administrative sessions, reset passwords on internet-facing systems, enforce robust password policies, and utilize the PBKDF2 algorithm for storing credentials. Monitoring logs for unauthorized activity and enabling phishing-resistant multi-factor authentication are also crucial steps.

This incident was initially uncovered by security researcher Volodymyr Diachenko, who found a server containing thousands of login credentials for firewalls and VPNs across 194 countries. The server also hosted the attackers’ tools and scripts, illustrating the potential for credential reuse and poor password hygiene to be exploited by cybercriminals.

The FortiBleed attack underscores the critical need for rigorous cybersecurity measures and highlights the ongoing risk perimeter devices pose as entry points for attackers.

The Hacker News Tags:admin accounts, CISA, credential breach, Cybersecurity, Firewall, FortiBleed, Fortinet, global campaign, multi-factor authentication, network security, password hygiene, password protection, security protocols, threat intelligence, VPN security

Post navigation

Previous Post: eFAQ Exposes Coordinated Online Reputation Attack
Next Post: Critical Flaws in Chrome Extensions Risk Millions

Related Posts

Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection The Hacker News
New YiBackdoor Malware Shares Major Code Overlaps with IcedID and Latrodectus New YiBackdoor Malware Shares Major Code Overlaps with IcedID and Latrodectus The Hacker News
Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in “Zero Disco’ Attacks Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in “Zero Disco’ Attacks The Hacker News
OpenAI Bans ChatGPT Accounts Used by Russian, Iranian and Chinese Hacker Groups OpenAI Bans ChatGPT Accounts Used by Russian, Iranian and Chinese Hacker Groups The Hacker News
WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide The Hacker News
Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Key Cybersecurity Updates: Apple, Delta, AWS Announcements
  • Global Crackdown on SocGholish Malware Cleans Thousands of Sites
  • Critical Flaws in Chrome Extensions Risk Millions
  • CISA Urges Fortinet Users to Secure Devices Amid Attack
  • eFAQ Exposes Coordinated Online Reputation Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Key Cybersecurity Updates: Apple, Delta, AWS Announcements
  • Global Crackdown on SocGholish Malware Cleans Thousands of Sites
  • Critical Flaws in Chrome Extensions Risk Millions
  • CISA Urges Fortinet Users to Secure Devices Amid Attack
  • eFAQ Exposes Coordinated Online Reputation Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark