FortiBleed Is Still Active, Locking Organizations Out 

Yesterday, the FBI and the U.S. Secret Service published a joint Cybersecurity Advisory on FortiBleed, the active global credential compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.

Today, the SOCRadar Threat Research Unit, which first documented FortiBleed in June, published a new report to help organizations defend or triage the Fortinet exposure. It adds field-response detail that changes how you should scope, hunt and remediate. It also includes what is operationally relevant right now: what has changed since the earlier reporting, the indicators to hunt on today, and the actions that actually close the gap.

Here’s the new report: FortiBleed Is Still Active, Locking Organizations Out, 

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading