threat-intel
FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists
High
Summary
The FortiBleed campaign, spearheaded by threat actors likely originating from Russia, has compromised over 430,000 FortiGate firewalls globally, resulting in the theft of more than 110 million credentials. Attackers utilize a Golang-based sniffer tool, FortigateSniffer, to passively capture authentication traffic from the firewalls, exploiting the built-in diagnostic command. This ongoing campaign is targeting SMBs, particularly in the US and India, and has broader implications across numerous sectors.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
