1 link tagged with all of: credential-theft + cisa + vpn + fortinet
Click any tag below to further narrow down your results
Links
CISA warns that a Russian-speaking threat actor has harvested 86,644 valid logins from internet-facing FortiGate firewalls and VPNs using SSL VPN interception, GPU-powered hash cracking, and brute-force attacks. Major government entities and critical infrastructure providers are affected. CISA advises resetting credentials, enforcing PBKDF2 for admin logins, enabling phishing-resistant MFA, and tightening management access.
- 86,644 valid FortiGate credentials—about half of all internet-exposed Fortinet devices—were harvested via SSL VPN interception and GPU-cracked passwords, hitting government and critical infrastructure targets across 194 countries.
- Attackers ran 1.16 billion credential checks against 320,000 FortiGate devices and 2.1 billion brute-force attempts on 160,000+ Microsoft SQL servers, fully compromising at least four organizations.
- Huntress found 845 of its partner organizations directly affected by matching leaked IPs against its own data.
- CISA is urging immediate credential resets, session termination, a switch to PBKDF2 for admin password storage, phishing-resistant MFA, and locking down management interfaces to known IPs.