De gevaarlijkste inbraak van deze week ging niet door de voordeur van de slachtoffers, maar via hun sleutelbeheerder.

Elke dag een nieuwe vraag die je kunt beantwoorden op https://www.ccinfo.nl

Weet u welke externe partijen toegang hebben tot de firewalls en systemen van uw organisatie?

#Cybersecurity #Fortinet #SupplyChain #Informatiebeveiliging #Belgie

📰 FortiSandbox Vulnerabilities Chained for Root-Level Takeover, Active Exploits in Wild

🚨 ACTIVE EXPLOITATION: Threat actors are chaining three FortiSandbox vulnerabilities (CVE-2026-39813, et al.) for unauthenticated RCE and full root takeover. Patch immediately to prevent sandbox compromise. #infosec #vulnerability #fortinet

🌐 cyber[.]netsecops[.]io

🔗 https://cyber.netsecops.io/articles/exploitation-of-multiple-fortisandbox-vulnerabilities-observed-in-the-wild/?u…

FortiBleed campaign used custom FortiGate sniffer to steal credentials

Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials.

BleepingComputer
Belgium has suffered a large-scale cyberattack affecting at least 270 organizations, including schools and administrative systems. The breach reportedly exploited vulnerabilities in Fortinet software. Experts estimate that over 110 million accounts may have been impacted.
https://paralell.eu/it/web/belgiya-razsledva-masthabna-kiberataka/
#Cybersecurity #Belgium #Hacking #Fortinet #DataBreach
Белгия разследва мащабна кибератака

Мащабна кибератака в Белгия е засегнала стотици организации чрез уязвимости във Fortinet, разследването продължава - Паралел

Паралел

A campanha cibernética FortiBleed está a visar mais de 430 mil dispositivos FortiGate da Fortinet em todo o mundo. Estes ataques utilizam ferramentas personalizadas para intercetar e roubar credenciais de autenticação diretamente de firewalls 🔒

🔗 https://tugatech.com.pt/t86025-fortinet-enfrenta-ataques-da-campanha-fortibleed-em-430-mil-firewalls-mundiais

#fortinet 

Fortinet enfrenta ataques da campanha FortiBleed em 430 mil firewalls mundiais

A campanha cibernética em grande escala conhecida como FortiBleed está a visar ativamente mais de 430 mil dispositivos FortiGate da Fortinet em todo o mundo. De

TugaTech

En it-sikkerheds-ekspert og Forsvarets Efterretningstjeneste opfordrer danske #Fortinet -kunder til at tage en række forholds-regler i kølvandet på et omfattende data-læk

I en omfattende cyber-aktion har stribevis af virksomheder verden over fået lækket login-oplysningerne til de sikkerheds-løsninger, der normalt hjælper med at holde ubudne gæster ude af deres it-systemer

Det er konsekvensen af den såkaldte Fortibleed-kampagne
https://ing.dk/artikel/dsv-maersk-og-dansk-politi-ramt-af-globalt-datalaek-fe-advarer-danske-virksomheder (paywalled)

DSV, Mærsk og dansk politi ramt af globalt datalæk: FE advarer danske virksomheder | Ingeniøren

En it-sikkerhedsekspert og Forsvarets Efterretningstjeneste opfordrer danske Fortinet-kunder til at tage en række forholdsregler i kølvandet på et omfattende datalæk.

Ingeniøren

Ya know the thing I hate the most about #Fortinet? It isn't the ridiculously terrible code that has lead to numerous exploits. It isn't the absolutely shit hardware quality. It isn't even the fact that _every_ fucking product is called FortiSomething.

Although that last one is really fucking annoying.

It's that the FortiOS configuration is essentially a write once only thing. Any objects you create that become depended on by other objects, basically become immutable, or at least very firmly entrenched. To make changes or insert something new into the mix that changes the dependency hierarchy of objects will usually require massive changes. Often times, your only option is to delete huge sections of configuration, insert the new stuff, and then put the configuration right back again.

It fucking sucks.

Maybe they've fixed this in the 18+ months it has been since I have touched a Fortinet device, but I kind of doubt it. Fortinet has shown as a company, if nothing else, that they are dead set in their ways.

Please stop buying Fortinet products, you aren't buying security. You are paying money to have open exploits on your network, coupled with terrible network management tools.

Massive breach spills credentials for thousands of sensitive networks

Researchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself.

#Fortinet #databreach #security #cybersecurity #hackers #hacking #hacked

https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks/

Massive breach spills credentials for thousands of sensitive networks

The affected include Oracle, Lenovo, FedEx, a NATO contractor, and Fortinet.

Ars Technica

NCSC Warns Fortinet Customers of Credential Theft Fallout

A massive database of 75,000 stolen credentials, including usernames, email addresses, and passwords, has been discovered, putting organisations like Oracle, Spotify, and AT&T at risk. The leak, dubbed "FortiBleed," affects customers in 194 countries and over 21,000 domains, with nearly half of all internet-accessible Fortinet firewalls…

https://osintsights.com/ncsc-warns-fortinet-customers-of-credential-theft-fallout?utm_source=mastodon&utm_medium=social

#Fortinet #CredentialTheft #Fortibleed #EmergingThreats #SupplyChain

NCSC Warns Fortinet Customers of Credential Theft Fallout

Fortinet customers face credential theft risk, learn how to protect yourself now and prevent data breaches effectively online today.

OSINTSights

FortiBleed: Angreifer nutzen ältere Schwachstellen gegen FortiGate-Geräte - Fortinet-Blog Update 19. juni 2026

https://www.all-about-security.de/fortibleed-angreifer-nutzen-aeltere-schwachstellen-gegen-fortigate-geraete/

#fortinet

FortiBleed: Angreifer nutzen ältere Schwachstellen aus

FortiBleed zielt auf FortiGate-Geräte. Erfahren Sie, wie Angreifer ältere Schwachstellen mit Brute-Force-Methoden ausnutzen.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit