
- الصفحة الرئيسية
- نشرات التهديدات
- NCSC-TAD-2605-001
NCSC-TAD-2605-001
الرقم المرجعي: NCSC-TAD-2605-001CVSS 0
FortiBleed leak exposes Fortinet VPN credentials
- نوع التهديد:
- غير متوفر
- مستوى المشاركة (TLP):
- CLEAR
- CVE:
- غير متوفر
نظرة عامة
FortiBleed is a cybersecurity incident involving the exposure of VPN credentials from Fortinet FortiGate devices. The leaked data reportedly includes usernames, email addresses, and passwords that could allow unauthorized access. The data is believed to have been collected through a combination of older Fortinet vulnerabilities, brute-force password attacks, stolen configuration files, and credentials obtained from previous security breaches. Security researchers believe the dataset is genuine, although the exact source of the data remains under investigation
إجراءات الحد من المخاطر والإجراءات الفورية
- 01
Rotate passwords associated with Fortinet VPN and administrative interfaces.
- 02
Enforce MFA.
- 03
Examine gateway logs for suspicious activity.
- 04
Monitor for exposed employee credentials.

