WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away

Networking cables plugged into a patch panel, showcasing data center connectivity.
Illustrative photo.Photo by Brett Sayles on Pexels

What happened

FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls (a barrier that decides which network traffic may pass), has compromised 86,644 devices and is locking out admins. What makes this advisory different from a typical IOC list is how much it reveals about the attackers themselves.

The operators behind FortiBleed accidentally exposed their backend infrastructure through an open directory, allowing investigators to see how the operation worked from the inside: how targets were selected, how stolen credentials were checked, and how access was prepared for sale. Secret Service issued a joint advisory about FortiBleed , and the headline number alone is worth sitting with: more than 86,644 compromised Fortinet FortiGate devices across 194 countries, according to SOCRadar’s verification. It’s something arguably more uncomfortable, a campaign built entirely on credentials that were already out there, reused, leaked, or sitting behind weak hashing nobody got around to replacing.

Sources & evidence