Yesterday, the FBI and the U.S. Secret Service published a joint Cybersecurity Advisory on FortiBleed, the active global credential compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.
Today, the SOCRadar Threat Research Unit, which first documented FortiBleed in June, published a new report to help organizations defend or triage the Fortinet exposure. It adds field-response detail that changes how you should scope, hunt and remediate. It also includes what is operationally relevant right now: what has changed since the earlier reporting, the indicators to hunt on today, and the actions that actually close the gap.
Here’s the new report: FortiBleed Is Still Active, Locking Organizations Out,
Related
This entry was posted on October 7, 2026 at 1:56 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
FortiBleed Is Still Active, Locking Organizations Out
Yesterday, the FBI and the U.S. Secret Service published a joint Cybersecurity Advisory on FortiBleed, the active global credential compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.
Today, the SOCRadar Threat Research Unit, which first documented FortiBleed in June, published a new report to help organizations defend or triage the Fortinet exposure. It adds field-response detail that changes how you should scope, hunt and remediate. It also includes what is operationally relevant right now: what has changed since the earlier reporting, the indicators to hunt on today, and the actions that actually close the gap.
Here’s the new report: FortiBleed Is Still Active, Locking Organizations Out,
Share this:
Like this:
Related
This entry was posted on October 7, 2026 at 1:56 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.