Massive Fortinet breach exposes credentials of major organizations

Researchers have uncovered a large-scale compromise of Fortinet firewalls that exposed plaintext credentials for nearly 74,000 devices across 194 countries. The breach affects organizations including Oracle, Chevron, Lenovo, FedEx, and Fortinet itself, along with a NATO defense contractor.

Bob Diachenko, a security researcher, discovered the data after accessing the attackers' command-and-control server. The exposed information includes credentials for devices in industries such as IT services, telecommunications, and financial services. Other affected entities listed in the database include Foxconn, Samsung, Comcast, Siemens, PwC, and Accenture.

The attackers, described as Russian-speaking and criminally motivated, used mass scanning and a custom binary to target FortiGate remote login endpoints. They then employed a 45-GPU cluster to crack authentication hashes, enabling lateral movement into systems like Microsoft Active Directory. Kevin Beaumont confirmed that the credentials remain valid and that most compromised devices stayed online as of Wednesday morning.

Hudson Rock researchers noted that classified defense documents were exfiltrated from a Turkish NATO contractor. The compromised devices represent roughly half of all Internet-facing Fortinet firewalls. Diachenko, Beaumont, and Hudson Rock urged affected organizations to check their networks immediately.

संबंधित लेख

US federal agencies have disclosed that Russian military intelligence compromised thousands of small office and home routers, urging owners to take immediate protective measures.

AI द्वारा रिपोर्ट किया गया

The FBI, BND and BfV warn of attacks by Russian state hackers on TP-Link routers and WLAN extenders. The Fancy Bear group has infiltrated thousands of devices worldwide to steal sensitive data. In Germany, 30 affected devices have already been detected.

Executives at West Pharmaceutical Services revealed details of a recent cybersecurity breach during a fireside chat at the Bank of America Global Healthcare Conference. The company issued an 8-K filing the previous evening after detecting an intruder in its systems. Officials described shutting down global operations to assess the situation.

AI द्वारा रिपोर्ट किया गया

DentaQuest has confirmed a cybersecurity incident involving unauthorized access to part of its network. Health data linked to 2.6 million accounts appeared on a public breach listing this week.

यह वेबसाइट कुकीज़ का उपयोग करती है

हम अपनी साइट को बेहतर बनाने के लिए विश्लेषण के लिए कुकीज़ का उपयोग करते हैं। अधिक जानकारी के लिए हमारी गोपनीयता नीति पढ़ें।
अस्वीकार करें