Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
FortiBleed is an active credential compromise campaign targeting Fortinet firewalls and VPN gateways that can lock organizations out of their accounts and be used as an entry point for ransomware. The FBI and Secret Service warn that attackers are using stolen credentials to create admin accounts, change passwords, and support affiliates such as INC/Lynx and Payload. #FortiBleed #Fortinet #INC_Lynx #Payload

Keypoints

  • FortiBleed targets Fortinet firewalls and VPN gateways.
  • Attackers can disable accounts or change passwords to lock users out.
  • The campaign has been linked to ransomware affiliate access.
  • SOCRadar found the operation was broader than initially understood.
  • The FBI and Secret Service recommend restricting internet administration and resetting credentials.

Read More: https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/