Full Report
Tens of thousands more victims and more ransomware groups getting in on the act
Analysis Summary
# Vulnerability: FortiBleed Credential Exploitation Campaign
## CVE Details
*Note: The provided text describes a large-scale campaign ("FortiBleed") rather than a single new zero-day CVE. It leverages a combination of credential stuffing, infostealer data, and potentially older, unpatched vulnerabilities to gain initial access.*
- **CVE ID:** N/A (Campaign-based exploitation)
- **CVSS Score:** N/A (High Impact)
- **CWE:** CWE-287 (Improper Authentication), CWE-798 (Use of Hardcoded Credentials/Credential Stuffing)
## Affected Systems
- **Products:** Fortinet FortiGate Firewalls, SSL VPN Gateways.
- **Versions:** All versions lacking phishing-resistant MFA and those with internet-facing management interfaces.
- **Configurations:** Internet-facing management access, systems with weak password policies, and devices where administrative sessions are not periodically terminated.
## Vulnerability Description
The "FortiBleed" campaign is a sophisticated credential-based attack. Threat actors utilize credentials obtained from third-party breaches and infostealer logs to perform credential stuffing and password spraying against Fortinet devices. Once initial access is gained, attackers extract password hashes directly from the compromised devices. These hashes are then cracked offline using GPU-accelerated clusters to gain high-level administrative access.
## Exploitation
- **Status:** Actively exploited in the wild (86,644+ compromised devices identified).
- **Complexity:** Low (utilizes automated credential stuffing/spraying).
- **Attack Vector:** Network (Internet-facing gateways).
## Impact
- **Confidentiality:** Total (Extraction of system hashes and internal network data).
- **Integrity:** Total (Creation of new unauthorized accounts; modification/deletion of existing administrative accounts).
- **Availability:** Total (Victims are frequently locked out of their own devices, leading to ransomware deployment).
## Remediation
### Patches
- While no specific single patch is cited for this campaign, organizations should ensure all FortiOS firmware is updated to the latest version to mitigate known vulnerabilities that may facilitate hash extraction.
### Workarounds
- **Restrict Access:** Immediately disable or restrict internet-facing management interfaces (Local-In policies).
- **Session Management:** Terminate all active administrative and VPN sessions to clear potentially hijacked sessions.
- **Authentication:** Enforce a global password reset and mandate **phishing-resistant Multi-Factor Authentication (MFA)**.
- **Access Control:** Implement IP allow-listing for administrative access.
## Detection
- **Indicators of Compromise:**
- Unauthorized new administrative accounts not created by internal IT.
- Sudden deletion or password changes of legitimate administrative accounts.
- Large volumes of failed login attempts from external IP addresses (Credential Stuffing).
- **Detection methods and tools:**
- Review system logs for unusual account creation or modification.
- Monitor for lateral movement originating from FortiGate devices into the internal network.
- Consult the FBI/USSS joint advisory for specific IP/domain IoCs.
## References
- **FBI/USSS Joint Advisory:** hxxps[://]www[.]ic3[.]gov/CSA/2026/261006[.]pdf
- **SOCRadar Research:** hxxps[://]socradar[.]io (Referenced in article)
- **Original Article:** hxxps[://]www[.]theregister[.]com/2026/10/07/fortibleed_fbi_advisory/ (Defanged)