FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists
FortiBleed attackers use a Golang-based sniffer to exploit 430,000 FortiGate firewalls globally, stealing 110 million credentials in an ongoing campaign. This attack highlights significant risks in firewall security configurations.
Prioritize patching FortiGate devices and review credential hygiene across your network. Consider deploying behavioral monitoring tools to detect unusual data exfiltration patterns.
FortiBleed attackers have leveraged a custom Golang-based sniffer to compromise over 430,000 FortiGate firewalls globally. The campaign has successfully stolen 110 million credentials, showcasing the scale and sophistication of the operation.
The attackers exploit vulnerabilities in firewall configurations to infiltrate networks, emphasizing the need for strict access controls and timely patching. Organizations relying on FortiGate devices are particularly at risk due to the wide deployment of these firewalls.
Defenders should immediately assess their FortiGate firewall setups for vulnerabilities, apply relevant updates, and enforce multi-factor authentication. Advanced monitoring tools can help detect unusual activity indicative of credential theft or exfiltration attempts.