CISA Urges Hardening Fortinet ... Note

CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure

CISA has identified a global cyber threat targeting internet-accessible Fortinet devices, including firewalls and VPN gateways. This activity, known as FortiBleed, has exposed credentials for approximately 74,000 Fortinet devices. Malicious actors are exploiting these leaked credentials to compromise government and private sector organizations. To mitigate this threat, CISA strongly advises affected Fortinet customers to take immediate action.Essential steps include terminating active sessions and resetting all VPN and administrative passwords, prioritizing internet-facing systems. Organizations must also verify the secure storage of administrator credentials, ensuring the use of the PBKDF2 algorithm and removing legacy hashes. Reviewing firewall, VPN, authentication, and domain controller logs is crucial for detecting suspicious activity. Implementing phishing-resistant multi-factor authentication for all remote access and administrative accounts is a high priority.Furthermore, reducing the attack surface by restricting access to Fortinet management interfaces from the public internet and disabling unnecessary accounts is recommended. CISA provides links to external resources for further information on the scope of the compromise. These resources detail the impact of the FortiBleed campaign on Fortinet devices worldwide. The provided information is for informational purposes and does not constitute an endorsement of any commercial entity or product.