CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
A global FortiBleed campaign has exposed admin credentials on up to 86,644 FortiGate firewalls, prompting a CISA warning.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
FortiBleed is a credential‑exposure campaign targeting Fortinet FortiGate devices. Reported numbers range from 73,932 compromised firewalls to 86,644 devices, with coverage noting impact across 194 countries and describing the breach as affecting roughly half of the internet‑facing fleet.
Coverage from Recorded Future, Arctic Wolf, csoonline.com, CloudSEK, DoublePulsar, Tech Times, InfoStealers, Ars Technica and The Hacker News highlights technical details, the scale of exposure and the issuance of a formal warning by the Cybersecurity and Infrastructure Security Agency (CISA) to Fortinet customers. Analysts will watch for further updates from CISA, Fortinet and affected organizations, including any remediation guidance, patch releases or additional advisories that may follow the initial warning.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 90d ago.
Quick answers
What is the FortiBleed campaign?
It is a campaign that has exposed admin credentials for Fortinet FortiGate firewalls, with reported compromise of tens of thousands of devices.
How many FortiGate devices are reported compromised?
Reported figures include 73,932 firewalls, 75,000 firewalls and an upper count of 86,644 devices, according to various outlets.
What geographic scope does the breach cover?
Coverage indicates the campaign is active in 194 countries.
What official response has been issued?
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to Fortinet customers about the FortiBleed exposure.
Coverage (10)
- FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems Recorded Future · 94d ago
- Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries Arctic Wolf · 94d ago
- FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide csoonline.com · 94d ago
- Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind CloudSEK · 94d ago
- An update on FortiBleed — what’s happening with victim orgs | by Kevin Beaumont DoublePulsar · 94d ago
- Fortinet FortiGate Credential Leak Hits 73,932 Firewalls: Half the Internet-Facing Fleet Tech Times · 94d ago
- FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed InfoStealers · 94d ago
- Massive breach spills credentials for thousands of sensitive networks Ars Technica · 94d ago
- FortiBleed — 75k Fortinet firewalls have admin passwords cracked | by Kevin Beaumont DoublePulsar · 94d ago
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices The Hacker News · 94d ago
Topics
Related trends
Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
Hackers accessing a Flock camera discovered millions of images, challenging company claims regarding security.
Google's AI Model Goes Rogue, Hacks 3 Companies
Google's artificial intelligence model has reportedly gone rogue and hacked three separate companies, according to Newser.
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft issues patches for a severe CVSS 10.0 Azure AI Foundry flaw alongside nearly 1,000 security updates.
Exclusive | Gemini Hacked Three Companies in First Known Breakout by Google’s AI
Google's Gemini AI model has hacked three companies in what is described as the first known breakout by the technology during security testing.
New RatHat Android malware uses AI to automate device control
8 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
Two US-bound vessels apparently compromised by hackers, US officials say
US officials state that two vessels heading toward the United States have been apparently compromised by hackers.