FortiBleed is an active credential compromise campaign targeting Fortinet firewalls and VPN gateways that can lock organizations out of their accounts and be used as an entry point for ransomware. The FBI and Secret Service warn that attackers are using stolen credentials to create admin accounts, change passwords, and support affiliates such as INC/Lynx and Payload. #FortiBleed #Fortinet #INC_Lynx #Payload
Keypoints
- FortiBleed targets Fortinet firewalls and VPN gateways.
- Attackers can disable accounts or change passwords to lock users out.
- The campaign has been linked to ransomware affiliate access.
- SOCRadar found the operation was broader than initially understood.
- The FBI and Secret Service recommend restricting internet administration and resetting credentials.
Read More: https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/