Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns of Critical Windows Ancillary Function Driver Zero-Day Exploited in Attacks
August 13, 2026
Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations
August 13, 2026
Jewelbug APT Hijacks Browsers to Steal Cookies, Spy on Government Networks
August 13, 2026
Home/CyberSecurity News/CISA Warns of Critical Fortinet FortiBleed Vulnerability CVE-2023-25610
CyberSecurity News

CISA Warns of Critical Fortinet FortiBleed Vulnerability CVE-2023-25610

Key Takeaways CISA has issued an urgent advisory regarding “FortiBleed,” a widespread credential exposure impacting Fortinet devices. Tens of thousands of internet-facing Fortinet...

Marcus Rodriguez
Marcus Rodriguez
June 19, 2026 4 Min Read
52 0

Key Takeaways

  • CISA has issued an urgent advisory regarding “FortiBleed,” a widespread credential exposure impacting Fortinet devices.
  • Tens of thousands of internet-facing Fortinet systems, including FortiGate firewalls and SSL VPN gateways, have had associated credentials compromised.
  • The exposure affects government and private sector entities globally, with threat actors leveraging stolen credentials for unauthorized access.
  • While no specific CVE is linked, the campaign highlights risks from credential leaks and inadequate security configurations.
  • CISA recommends immediate actions, including session termination, password resets, enhanced credential storage, and MFA implementation.

CISA Issues Urgent Warning on Widespread FortiBleed Credential Exposure

The Cybersecurity and Infrastructure Security Agency (CISA) has released a critical alert, urging organizations worldwide to fortify their Fortinet infrastructure. This follows reports of a large-scale credential exposure campaign dubbed “FortiBleed,” which has seen threat actors exploit compromised login details tied to tens of thousands of internet-accessible Fortinet systems.

Table Of Content

  • Key Takeaways
  • CISA Issues Urgent Warning on Widespread FortiBleed Credential Exposure
  • Global Reach of FortiBleed Campaign
  • CISA’s Immediate Recommendations for Fortinet Users
  • The Evolving Threat Landscape
  • What You Should Do

According to CISA, the “FortiBleed” activity involves leaked credentials associated with approximately 74,000 Fortinet devices. These include widely deployed FortiGate firewalls and SSL VPN gateways, critical components for network security and remote access.

The impact of this exposure is extensive, affecting both government and private-sector organizations across numerous regions. This raises significant concerns about potential unauthorized network access, lateral movement by attackers, and subsequent data exfiltration or malware deployment.

Global Reach of FortiBleed Campaign

Security researchers and threat intelligence firms, including SOCRadar, Hudson Rock, and Arctic Wolf, have independently confirmed the global scale of the FortiBleed campaign. Their reports indicate that the activity spans over 190 countries, underscoring the pervasive nature of the threat.

A significant factor contributing to this widespread compromise is the direct internet accessibility of many affected devices. Such exposure makes these systems prime targets for threat actors seeking an initial foothold into organizational networks.

The primary danger arises from attackers leveraging these legitimate, albeit compromised, credentials to bypass conventional security measures. Once inside, malicious actors can escalate privileges, traverse networks laterally, and potentially deploy malicious payloads or exfiltrate sensitive information.

CISA’s Immediate Recommendations for Fortinet Users

In response to the escalating threat, CISA has strongly advised organizations utilizing Fortinet products to implement immediate defensive measures. A crucial first step involves terminating all active SSL VPN and administrative sessions to prevent ongoing unauthorized access.

Organizations must also undertake a comprehensive password reset for all credentials associated with Fortinet devices, especially those exposed to the public internet. This should be accompanied by the enforcement of robust password policies to prevent future compromises. Securing credential storage is another vital mitigation step.

CISA specifically recommends verifying that administrator credentials are safeguarded using Password-Based Key Derivation Function 2 (PBKDF2), a more secure hashing algorithm. Organizations should promptly remove or update any older, weaker hashing mechanisms in line with Fortinet’s most recent security guidelines.

Additionally, thorough log reviews are essential. This includes meticulous analysis of firewall logs, VPN access records, authentication logs, and domain controller activity for any indicators of suspicious behavior. Anomalies such as unusual login attempts, the creation of unauthorized accounts, or unexpected configuration alterations could signal a compromise.

To further bolster defenses, CISA advocates for the widespread implementation of phishing-resistant multi-factor authentication (MFA) across all remote access points and administrative interfaces. This critical layer of protection remains effective even if primary credentials have been exposed.

Reducing the overall attack surface is another key priority. Administrators should ensure that Fortinet management interfaces are not directly exposed to the public internet. Access should be strictly limited to trusted internal networks, and any unnecessary or unauthorized accounts must be immediately identified and removed.

The Evolving Threat Landscape

The FortiBleed campaign starkly illustrates the increasing prevalence and danger of credential-based attacks. Threat actors are progressively shifting away from solely exploiting software vulnerabilities, instead leveraging stolen login data as a primary attack vector.

This incident underscores the critical importance of proactive security measures, including strong authentication protocols, diligent credential management practices, and continuous monitoring of network activity. While no specific CVE has been directly linked to this particular campaign, the sheer scale and impact of the exposure highlight how misconfigurations and credential leaks can create significant security vulnerabilities.

Organizations are strongly encouraged to review CISA’s guidance and relevant threat intelligence reports to accurately assess their exposure and take decisive action. As cyber adversaries continually refine their tactics, securing edge devices such as firewalls and VPN gateways remains paramount for maintaining comprehensive network security.

What You Should Do

  • Terminate Sessions: Immediately end all active SSL VPN and administrative sessions on Fortinet devices.
  • Reset Passwords: Reset all passwords associated with Fortinet devices, especially those accessible from the internet. Enforce strong, unique passwords.
  • Secure Credential Storage: Verify that administrator credentials are protected using PBKDF2. Remove or update older, weaker hashing mechanisms.
  • Enable MFA: Implement phishing-resistant multi-factor authentication (MFA) across all remote access points and administrative interfaces.
  • Review Logs: Conduct thorough reviews of firewall, VPN, authentication, and domain controller logs for any signs of unusual activity.
  • Restrict Access: Ensure Fortinet management interfaces are not exposed to the public internet. Limit access to trusted internal networks.
  • Remove Unnecessary Accounts: Identify and remove any unnecessary or unauthorized user accounts on Fortinet devices.
  • Stay Informed: Regularly consult CISA advisories and Fortinet security updates for the latest recommendations and patches.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarephishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

China-Linked Showboat Malware Targets Telecoms with Linux Persistence

Next Post

INC Ransomware Leverages Rust Encryptors for Windows, Linux, and ESXi Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Threat Actors Exploit Google Workspace for Phishing and Scam Campaigns
August 13, 2026
Critical Microsoft SharePoint CVE-2023-29357 Actively Exploited
August 13, 2026
Cloudflare Reports Record DDoS Attacks Exceeding 1 Tbps in H1 2023
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us