FortiBleed campaign used custom FortiGate sniffer to steal credentials
The FortiBleed campaign deployed custom packet sniffers on compromised FortiGate firewalls to harvest authentication credentials in transit — elevating the urgency for any organisation still running unpatched Fortinet edge devices.
Summary written by editorial AI · Source link below
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. [...]
Editorial Analysis
Fortinet devices are pervasive in European Mittelstand networks; credential harvesting at the firewall level means full network compromise may already have occurred silently.
Rotate all credentials that traversed FortiGate appliances and verify firmware is patched against all known FortiOS vulnerabilities.
Attackers installed credential-harvesting sniffers on Fortinet firewalls — assume compromise if devices were unpatched and rotate all network credentials.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d