Click any tag below to further narrow down your results
Links
CISA warns that a Russian-speaking threat actor has harvested 86,644 valid logins from internet-facing FortiGate firewalls and VPNs using SSL VPN interception, GPU-powered hash cracking, and brute-force attacks. Major government entities and critical infrastructure providers are affected. CISA advises resetting credentials, enforcing PBKDF2 for admin logins, enabling phishing-resistant MFA, and tightening management access.
- 86,644 valid FortiGate credentials—about half of all internet-exposed Fortinet devices—were harvested via SSL VPN interception and GPU-cracked passwords, hitting government and critical infrastructure targets across 194 countries.
- Attackers ran 1.16 billion credential checks against 320,000 FortiGate devices and 2.1 billion brute-force attempts on 160,000+ Microsoft SQL servers, fully compromising at least four organizations.
- Huntress found 845 of its partner organizations directly affected by matching leaked IPs against its own data.
- CISA is urging immediate credential resets, session termination, a switch to PBKDF2 for admin password storage, phishing-resistant MFA, and locking down management interfaces to known IPs.
CISA has directed U.S. federal agencies to fix a critical authentication bypass in Check Point Remote Access and Mobile Access VPNs (CVE-2026-50751) by June 11. The flaw, exploited by Qilin ransomware affiliates since early May, affects IKEv1 deployments without machine certificates. Check Point released updates and mitigation steps for unpatched environments.
- CVE-2026-50751 lets attackers bypass authentication entirely on Check Point Remote Access/Mobile Access VPNs using legacy IKEv1 setups without machine certificates.
- Qilin ransomware affiliates have been exploiting it since May 7, breaching a few dozen organizations, with exploitation spiking over the weekend.
- CISA added it to the KEV catalog and gave federal agencies until June 11 to patch, citing VPN flaws as a top ransomware entry point.
- If patching isn't immediate, mitigations include disabling legacy clients, enforcing IKEv2-only, enabling updated IPS signatures, and requiring machine certificates.