FBI: FortiBleed attackers can lock organizations out of their own firewalls
What happened
Details from an FBI investigation into the ongoing FortiBleed attacks reveal that victims could be locked out of their own firewall (a barrier that decides which network traffic may pass) even as attackers remain logged in. The operators were also found ranking organizations based on their revenue and network structure, the FBI said in an advisory .
After gaining access to a backend server left exposed by the attackers, the FBI and US Secret Service have shared new details of an operation that has already affected more than 80,000 devices worldwide. The server gave investigators a look at the infrastructure behind the operation, including systems used to process stolen credentials, crack password hashes, and identify potential targets.
“FortiBleed isn’t a vulnerability story anymore,” said Muhammad Yahya Patel , vCISO, cybersecurity advisor EMEA at Huntress. “It’s a persistence story. The credentials were taken months ago. The question every organization needs to answer is whether they’re still being used right now.”
Key facts
- The operators were also — found: ranking organizations based on their revenue and network structure, the FBI said in an advisory
Sources & evidence
- CSO Online Reporting source
FBI: FortiBleed attackers can lock organizations out of their own firewalls ↗
https://www.csoonline.com/article/4232481/fbi-fortibleed-attackers-can-lock-organizations-out-of-their-own-firewalls.html