انتقل إلى المحتوى الرئيسي
English
logo
مستوى الخطورة: منخفضة
تسريب بيانات

الرقم المرجعي: NCSC-TAD-2605-001CVSS 0

FortiBleed leak exposes Fortinet VPN credentials

نوع التهديد:
غير متوفر
مستوى المشاركة (TLP):
CLEAR
CVE:
غير متوفر

نظرة عامة

FortiBleed is a cybersecurity incident involving the exposure of VPN credentials from Fortinet FortiGate devices. The leaked data reportedly includes usernames, email addresses, and passwords that could allow unauthorized access. The data is believed to have been collected through a combination of older Fortinet vulnerabilities, brute-force password attacks, stolen configuration files, and credentials obtained from previous security breaches. Security researchers believe the dataset is genuine, although the exact source of the data remains under investigation

إجراءات الحد من المخاطر والإجراءات الفورية

  1. 01

    Rotate passwords associated with Fortinet VPN and administrative interfaces.

  2. 02

    Enforce MFA.

  3. 03

    Examine gateway logs for suspicious activity.

  4. 04

    Monitor for exposed employee credentials.

المراجع