Tag

Fortigate

All articles tagged with #fortigate

FortiBleed Breach Exposes 86K FortiGate Devices in Global Credential Campaign
security2 months ago

FortiBleed Breach Exposes 86K FortiGate Devices in Global Credential Campaign

CISA warns Fortinet customers about FortiBleed, a global credential-stuffing and brute-force campaign targeting internet-facing FortiGate firewalls and VPN gateways, with 86,644 devices compromised as of June 19, 2026. The attack, attributed to Russian-speaking actors, proceeds in two steps: scanning for exposed Fortinet endpoints, then using leaked or organization credentials to gain access, before passively harvesting more credentials. Sectors most affected include telecom, government, and education, with the U.K. NCSC calling it a worldwide campaign; many admins’ passwords remain SHA-256-hashed from older FortiGate versions, though PBKDF2 hashing is used in newer FortiOS releases. Fortinet maintains the incident data likely comes from prior breaches and brute-forcing, not a current advisory. CISA recommends terminating active sessions, resetting passwords on internet-facing systems, enforcing PBKDF2, applying strong password policies, enabling phishing-resistant MFA, reviewing logs, and reducing attack surfaces to mitigate risk.

Nightmare-Eclipse Privilege Tools Breach FortiGate SSL VPN in the Wild
cyber-security4 months ago

Nightmare-Eclipse Privilege Tools Breach FortiGate SSL VPN in the Wild

Attackers used publicly released Nightmare-Eclipse privilege-escalation tools—BlueHammer, RedSun, and UnDefend—after compromising a FortiGate SSL VPN, marking the first in-the-wild use against a live enterprise. BlueHammer has been patched via CVE-2026-33825; RedSun and UnDefend remain unpatched zero-days. BeigeBurrow served as a covert C2. The intrusion involved VPN logins from Russia and other countries, with binary artifacts including FunnyApp.exe, RedSun.exe, undef.exe, and the BeigeBurrow domain staybud.dpdns.org. Mitigations include applying the April 2026 patch, scanning for artifacts in user-writable paths, reviewing VPN authentication logs for multi-country access, blocking agent.exe -server -hide, and applying the published YARA rule to detect BeigeBurrow.