An ecrime group has somehow gained access to 75k Fortinet firewall devices - dubbed Fortibleed

Blog https://www.infostealers.com/article/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure/

Check if your domain is impacted: https://www.hudsonrock.com/fortinet

I’ve verified the data is real. They’ve been dumping the Fortinet config - not sure how yet - and then cracking the passwords it appears. Data is being resold online. #fortibleed

Data looks like this, appears they validated creds too.

It’s similar to the Belsen Group thing, although that was a smaller collection of devices - prior thread

https://cyberplace.social/@GossiTheDog/113834848200229959

Kevin Beaumont (@[email protected])

Attached: 2 images A new group, Belsen Group, claim to have released Fortigate configs for 15k firewalls. #threatintel

Cyberplace

So there are definitely devices which weren't in the Belsen Group post back last year, in fact almost all of them weren't.

On how they got the passwords - until about a year ago, FortiOS (Fortinet firewall OS) stored admin passwords SHA-256 salted, which can be bruteforced.

In an update about a year ago, if installed and admins log in, passwords are stored much more securely - but most orgs won't be that condition yet. In other words, if you dump the config you could get the passwords.

FortiBleed — 75k Fortinet firewalls have admin passwords cracked

A look inside a massive dump of allowing access to organisations protected by Fortigate firewall solutions.

Medium

Lol, the #FortiBleed data was found in an opendir on a webserver 🤣 truly GenAI is going to take over 😜

"They accidentally left an open directory with artefacts, connection strings, tooling, scripts and data online. Analytics obtained via their cron jobs, bash histories, logs etc,"

https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.

A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.

BleepingComputer
#GAYINT list of impacted #FortiBleed domains (this is basically email addresses of admin accounts on the device btw) https://blog.gayint.org/intel/fortibleed.txt
#GAYINT list of impacted #FortiBleed IPs. Not all as I couldn't write the parser properly. http://owned.lab6.com/~gossi/research/public/fortibleed/some-fortibleed-ips.txt

Fortinet appear to be telling press the #Fortibleed breach is made up of prior breaches and brute forcing.. but I’ve seen the breach data and it includes many passwords not in prior dumps, and I’ve worked with impacted orgs and they report no brute forcing of impacted accounts.

I think there may be some confusion about this one - the brute forcing is the cracking of the passwords by the threat actor, which is done locally.

Watch this space on this one anyhoo.

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.

National Cyber Security Centre
@GossiTheDog the organisation I work for is not on the list, and I strongly suspect because we enforced MFA on all VPN connections from the beginning. (cf NCSC point, ACSC Essential Eight ...)
I don't know why orgs wouldn't use it 
@tjbutt58 @GossiTheDog ditto for the fortinets i support. admin interface only open from trusted IPs as well.