GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 17-Jun-2026 20:18:56 JST Kevin Beaumont Kevin Beaumont

    An ecrime group has somehow gained access to 75k Fortinet firewall devices - dubbed Fortibleed

    Blog https://www.infostealers.com/article/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure/

    Check if your domain is impacted: https://www.hudsonrock.com/fortinet

    I’ve verified the data is real. They’ve been dumping the Fortinet config - not sure how yet - and then cracking the passwords it appears. Data is being resold online. #fortibleed

    In conversation about 4 months ago from cyberplace.social permalink

    Attachments


    1. Domain not in remote thumbnail source whitelist: www.hudsonrock.com
      Hudson Rock - Infostealer Intelligence Solutions
      from @rockhudsonrock
      Powered by Hudson Rock's continuously augmented cybercrime database, composed of millions of machines compromised by Infostealers in global malware spreading campaigns.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 17-Jun-2026 20:23:18 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Data looks like this, appears they validated creds too.

      In conversation about 4 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/116/765/184/936/319/367/original/309beb6a558e64d0.jpeg
    • Embed this notice
      Greem (Graeme. Not Graham!) (greem@cyberplace.social)'s status on Wednesday, 17-Jun-2026 20:24:21 JST Greem (Graeme. Not Graham!) Greem (Graeme. Not Graham!)
      in reply to

      @GossiTheDog Squarely in "YIKES" territory, this one.

      In conversation about 4 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 17-Jun-2026 20:36:30 JST Kevin Beaumont Kevin Beaumont
      in reply to

      It’s similar to the Belsen Group thing, although that was a smaller collection of devices - prior thread

      https://cyberplace.social/@GossiTheDog/113834848200229959

      In conversation about 4 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cyberplace.social
        Kevin Beaumont (@GossiTheDog@cyberplace.social)
        from Kevin Beaumont
        Attached: 2 images A new group, Belsen Group, claim to have released Fortigate configs for 15k firewalls. #threatintel
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 17-Jun-2026 22:44:06 JST Kevin Beaumont Kevin Beaumont
      in reply to

      So there are definitely devices which weren't in the Belsen Group post back last year, in fact almost all of them weren't.

      On how they got the passwords - until about a year ago, FortiOS (Fortinet firewall OS) stored admin passwords SHA-256 salted, which can be bruteforced.

      In an update about a year ago, if installed and admins log in, passwords are stored much more securely - but most orgs won't be that condition yet.

      In conversation about 4 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/116/765/736/421/232/371/original/99378007b9a008a1.png

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 17-Jun-2026 23:21:58 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Wrote a blog about the #FortiBleed situation https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8?postPublishedType=initial

      In conversation about 4 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 18-Jun-2026 00:43:26 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Lol, the #FortiBleed data was found in an opendir on a webserver 🤣 truly GenAI is going to take over 😜

      "They accidentally left an open directory with artefacts, connection strings, tooling, scripts and data online. Analytics obtained via their cron jobs, bash histories, logs etc,"

      https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/

      In conversation about 4 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.bleepstatic.com
        FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
        from @BleepinComputer
        A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 18-Jun-2026 19:42:37 JST Kevin Beaumont Kevin Beaumont
      in reply to

      #GAYINT list of impacted #FortiBleed domains (this is basically email addresses of admin accounts on the device btw) https://blog.gayint.org/intel/fortibleed.txt

      In conversation about 4 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 18-Jun-2026 19:44:40 JST Kevin Beaumont Kevin Beaumont
      in reply to

      #GAYINT list of impacted #FortiBleed IPs. Not all as I couldn't write the parser properly. http://owned.lab6.com/~gossi/research/public/fortibleed/some-fortibleed-ips.txt

      In conversation about 4 months ago permalink

      Attachments


      1. Invalid filename.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jun-2026 05:10:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Fortinet appear to be telling press the #Fortibleed breach is made up of prior breaches and brute forcing.. but I’ve seen the breach data and it includes many passwords not in prior dumps, and I’ve worked with impacted orgs and they report no brute forcing of impacted accounts.

      I think there may be some confusion about this one - the brute forcing is the cracking of the passwords by the threat actor, which is done locally.

      Watch this space on this one anyhoo.

      In conversation about 4 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/116/772/900/051/768/508/original/4263c41be37060e4.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jun-2026 05:21:32 JST Kevin Beaumont Kevin Beaumont
      in reply to

      NCSC UK advice on Fortibleed: https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways

      In conversation about 4 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.ncsc.gov.uk
        Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
        Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 19-Jun-2026 05:33:43 JST Kevin Beaumont Kevin Beaumont
      in reply to

      To be transparent about this, a threat actor has been claiming they have an exploit to get FortiOS device password hashes remotely from config for the past month. It’s currently unclear how. They claim it’s an exploit of an unpatched vuln. Their claims predate the discovery of this dump.

      If I end up having to set up another FortiGate firewall honeypot to figure out what’s going on.. I’ll British tut and get on with it.

      In conversation about 4 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jun-2026 01:06:07 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Some kind #FortiBleed victims got me to look at their situations. Some IOCs performing remote config dumps:

      193.8.186.7
      80.75.212.113
      213.21.239.65

      Look for inbound TCP traffic to Fortigate devices. If seen log into the devices and look for config dump events from those IPs.

      Config dumps (including crackable password hashes) have been going on for around a month.

      If you have IPsec site to site VPN tunnels on the impacted Fortinets you need to rebuild the tunnels with new keys both ends.

      In conversation about 4 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jun-2026 01:07:51 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Canadian Centre for Cyber Security on #FortiBleed

      https://www.cyber.gc.ca/en/alerts-advisories/al26-014-fortibleed-leak-thousands-compromised-credentials-impacting-fortinet-devices

      In conversation about 4 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.cyber.gc.ca
        AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices - Canadian Centre for Cyber Security
        from @cybercentre_ca
        AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices
    • Embed this notice
      V4N4D1S (v4n4d1s@mastodon.social)'s status on Saturday, 20-Jun-2026 02:08:59 JST V4N4D1S V4N4D1S
      in reply to

      @GossiTheDog Did some IR on a box in the leak.
      Multiple IPs from 193.8.186.0/24. 213.21.239.65 found as well. No sign of 80.75.212.113.

      In conversation about 4 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jun-2026 02:19:00 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CloudSEK look at the open directory that had all the #FortiBleed tooling and data in it. It's a good report, although I disagree with their conclusion - it's still an absolutely truck load of creds, even if that particular opendir only had internal network details for a few thousand orgs. https://www.cloudsek.com/blog/inside-the-fortibleed-open-directory-a-technical-analysis-of-what-the-attacker-left-behind

      In conversation about 4 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cdn.prod.website-files.com
        Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind | CloudSEK
        An exposed attacker server has revealed FortiBleed’s complete operation—from credential harvesting and GPU-powered cracking to network intrusion and access sales. CloudSEK’s analysis separates verified compromises from inflated claims, uncovering what the attackers actually achieved.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 20-Jun-2026 18:10:40 JST Kevin Beaumont Kevin Beaumont

      Fortinet have put out a blog about FortiBleed finally - where they don’t mention configuration exports (which is definitely happening at scale, I have receipts) or password hash cracking (we have the bash history of the user doing it).. but instead link Fortibleed to a prior marketing blog called “Attacks at the speed of AI” 🤦♀️

      https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices?lctg=197390370

      In conversation about 4 months ago permalink
    • Embed this notice
      kjpax (kjpax@cyberplace.social)'s status on Saturday, 20-Jun-2026 18:24:29 JST kjpax kjpax
      in reply to

      @GossiTheDog Maybe they are meaning using the AI infrastructure to crack passwords at scale. Is that the speed of AI 😂

      In conversation about 4 months ago permalink
    • Embed this notice
      System Adminihater (systemadminihater@cyberplace.social)'s status on Saturday, 20-Jun-2026 19:18:11 JST System Adminihater System Adminihater
      in reply to

      @GossiTheDog someone needs to stop these people and F5

      In conversation about 4 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jun-2026 04:26:36 JST Kevin Beaumont Kevin Beaumont
      in reply to

      There's some more analysis of the #FortiBleed attack infrastructure here:
      https://zenox.ai/en/fortibleed-anatomy-of-the-fortibleed-campaign-based-on-the-server-that-the-attackers-themselves-left-exposed/

      It's not mentioned but they cracked around 170k AD account passwords. Also all the comments on the custom source is written in Russian.

      Also, there is a GenAI angle I missed - they used an open source pentesting AI agent framework to try to automate attacks. It doesn't look like that bit worked very well.

      In conversation about 4 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 23-Jun-2026 20:33:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      SOC Radar have a good write up for #FortiBleed too
      https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/

      And a free checker - includes downstream credential checker (e.g. cracked AD passwords etc) https://socradar.io/free-tools/fortibleed

      In conversation about 4 months ago permalink

      Attachments



    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 07-Oct-2026 17:58:55 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The FBI and US secret service have discovered #FortiBleed

      In conversation about 3 days ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/117/398/795/476/267/022/original/ba682e14895d2ab8.jpeg

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.