ACSC Issues Urgent Alerts on FortiBleed Threat as Fortinet Confirms Compromise of Over 30,000 Devices Globally

Published:

ACSC Issues Urgent Alerts on FortiBleed Threat as Fortinet Confirms Compromise of Over 30,000 Devices Globally

The Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate, has raised alarms over a significant security breach affecting Fortinet Firewalls and VPN Gateways. This incident, termed “FortiBleed,” has implications for organizations worldwide, highlighting the urgent need for enhanced cybersecurity measures.

On June 18, the ACSC issued an initial alert detailing an ongoing malicious campaign targeting Fortinet devices. This campaign primarily exploits exposed credentials and credential-based attacks, which can lead to further compromises and the exposure of additional credentials. The alert followed an analysis by SOCRadar, which underscored the extensive nature of the threat.

Nature of the Threat

The ACSC has indicated that the exploitation of these credentials could provide malicious actors with remote access to compromised devices and their connected networks. Such access allows attackers to modify various settings, including critical security controls. SOCRadar reports that the adversaries involved in this campaign are believed to be Russian-speaking and have successfully compromised over 30,000 devices across 200 countries, including Australia.

Once a device is infiltrated, attackers can use it as a listening post to monitor traffic and capture any additional credentials that may pass through. This creates a self-perpetuating cycle, enabling further compromises. The password list utilized by the attackers is not arbitrary; it consists of credentials previously leaked from Fortinet devices during earlier incidents. Many targeted organizations may not have updated their passwords since those breaches, rendering them particularly vulnerable.

Ongoing Developments

On June 22, the ACSC reissued its alert in light of updated guidance from Fortinet, which was made public the previous week. The ACSC urged affected organizations to review Fortinet’s blog post and additional recommendations regarding the ongoing threat.

Fortinet’s Situational Analysis report, published on June 19, clarified that the current situation does not arise from a new vulnerability within Fortinet products. Instead, it involves the reuse of credentials compromised in two earlier incidents from December 2025 and January 2026. Fortinet has reiterated the importance of adhering to the remediation steps outlined in previous advisories.

Recommended Actions for Organizations

In response to the ongoing threat, Fortinet has outlined a set of six recommendations that organizations should implement immediately on any compromised devices:

  1. Terminate all admin and VPN sessions and reset credentials: Organizations should terminate all active administrative sessions and reset all Fortinet VPN and administrative passwords, especially for internet-facing systems. Strong password policies must be enforced.
  2. Implement Multi-Factor Authentication (MFA): MFA should be enabled for all administrator and VPN user accounts to bolster security.
  3. Upgrade to the latest software versions: Organizations are advised to upgrade to the latest versions of Fortinet software (7.4, 7.6, or 8.0), which support PBKDF2 hashing of administrator credentials. Guidance should be followed to eliminate older legacy password settings.
  4. Validate configuration: A thorough review of firewall and VPN configurations is necessary to identify unauthorized changes. Comparing configurations to a known good state is recommended, with particular attention to unrecognized accounts.
  5. Check logs for suspicious activity: Organizations should monitor logs for unexpected administrator access from unknown IP addresses, as well as any signs of lateral movement or unauthorized configuration changes.
  6. Reduce attack surface and lock down management access: External management access should be restricted to trusted hosts, implemented through a local-in policy, or ideally, removed altogether from internet administration.

Fortinet has also highlighted its FortiGuard Incident Response service, allowing customers to request investigations into their networks.

For further details on this ongoing situation, organizations are encouraged to consult the original reporting source. Source: cyberwarriorsmiddleeast.com.

For ongoing coverage and breaking updates, visit our Latest News section.

Published on 2026-06-22 08:05:00 • By the Editorial Desk

Share post:

[tds_leads title_text="Subscribe" input_placeholder="Email address" btn_horiz_align="content-horiz-center" pp_checkbox="yes" pp_msg="SSd2ZSUyMHJlYWQlMjBhbmQlMjBhY2NlcHQlMjB0aGUlMjAlM0NhJTIwaHJlZiUzRCUyMiUyMyUyMiUzRVByaXZhY3klMjBQb2xpY3klM0MlMkZhJTNFLg==" f_title_font_family="653" f_title_font_size="eyJhbGwiOiIyNCIsInBvcnRyYWl0IjoiMjAiLCJsYW5kc2NhcGUiOiIyMiJ9" f_title_font_line_height="1" f_title_font_weight="700" f_title_font_spacing="-1" msg_composer="success" display="column" gap="10" input_padd="eyJhbGwiOiIxNXB4IDEwcHgiLCJsYW5kc2NhcGUiOiIxMnB4IDhweCIsInBvcnRyYWl0IjoiMTBweCA2cHgifQ==" input_border="1" btn_text="I want in" btn_tdicon="tdc-font-tdmp tdc-font-tdmp-arrow-right" btn_icon_size="eyJhbGwiOiIxOSIsImxhbmRzY2FwZSI6IjE3IiwicG9ydHJhaXQiOiIxNSJ9" btn_icon_space="eyJhbGwiOiI1IiwicG9ydHJhaXQiOiIzIn0=" btn_radius="3" input_radius="3" f_msg_font_family="653" f_msg_font_size="eyJhbGwiOiIxMyIsInBvcnRyYWl0IjoiMTIifQ==" f_msg_font_weight="600" f_msg_font_line_height="1.4" f_input_font_family="653" f_input_font_size="eyJhbGwiOiIxNCIsImxhbmRzY2FwZSI6IjEzIiwicG9ydHJhaXQiOiIxMiJ9" f_input_font_line_height="1.2" f_btn_font_family="653" f_input_font_weight="500" f_btn_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_btn_font_line_height="1.2" f_btn_font_weight="700" f_pp_font_family="653" f_pp_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_pp_font_line_height="1.2" pp_check_color="#000000" pp_check_color_a="#ec3535" pp_check_color_a_h="#c11f1f" f_btn_font_transform="uppercase" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjQwIiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGUiOnsibWFyZ2luLWJvdHRvbSI6IjM1IiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGVfbWF4X3dpZHRoIjoxMTQwLCJsYW5kc2NhcGVfbWluX3dpZHRoIjoxMDE5LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" msg_succ_radius="2" btn_bg="#ec3535" btn_bg_h="#c11f1f" title_space="eyJwb3J0cmFpdCI6IjEyIiwibGFuZHNjYXBlIjoiMTQiLCJhbGwiOiIxOCJ9" msg_space="eyJsYW5kc2NhcGUiOiIwIDAgMTJweCJ9" btn_padd="eyJsYW5kc2NhcGUiOiIxMiIsInBvcnRyYWl0IjoiMTBweCJ9" msg_padd="eyJwb3J0cmFpdCI6IjZweCAxMHB4In0="]

Popular

More like this
Related

Tokyo court grants legal protection to human voices in AI clone case involving Kenjiro Tsuda

A Tokyo court has granted legal protection to human voices in a significant ruling involving Kenjiro Tsuda, a prominent anime voice actor known for his distinctive baritone. The decision, reported by Emirates 247, marks the first legal acknowledgment of an…

Bank of England governor calls for rigorous AI testing before regulation

The Governor of the Bank of England, Andrew Bailey, has emphasised the need for "rigorous" testing of artificial intelligence (AI) before implementing regulations. In his inaugural article for Substack, Bailey stated that while the risks associated with AI are "real…

Eleven Emirati AI experts engage with Canadian institutions to enhance responsible AI applications

Eleven Emirati artificial intelligence experts from the National Experts Programme’s Artificial Intelligence track (NEP-AI) are currently engaging with leading Canadian institutions to explore the translation of advanced AI research into responsible applications. This international study visit, which commenced on Monday…

Kaspersky uncovers phishing campaign impersonating Zoom and Docusign targeting corporate emails

Kaspersky has identified an ongoing phishing campaign that impersonates official emails from Zoom and Docusign, targeting corporate accounts across various regions, including the Middle East, Latin America, and Western Europe. This revelation highlights the persistence of traditional phishing tactics, even…