A Russian-speaking threat actor stole configuration files containing credentials from nearly 74,000 Fortinet firewalls and VPN gateways, which were then accidentally exposed on a public server. The article does not specify a CVE, CVSS score, affected versions, or a fixed version for this credential leak. Organizations using Fortinet devices should immediately audit and rotate all administrative and VPN credentials.
A Russian-speaking cybercriminal group has stolen credentials contained in the configuration files of nearly 74,000 Fortinet firewalls and VPN gateways around the world. The data was accidentally exposed by the group on a server, along with other artifacts and tools, and the exposure was noticed by security researcher Volodymyr “Bob” Diachenko. He raised the alarm last weekend, and other researchers have since analyzed the exposed dataset. “I have worked with several orgs listed, and can … More → The post 74,000 Fortinet firewall credentials exposed in FortiBleed data leak appeared first on Help Net Security .