Massive breach spills credentials for thousands of sensitive networks
Researchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself.
Nearly 74,000 Fortinet devices from more than 21,000 IP addresses in 194 countries have been compromised and their plaintext credentials exposed online, Bob Diachenko, a security researcher and head of SecurityDiscovery.com, said online and in an interview. He said he found the data after gaining access to the attackers’ command-and-control server and other infrastructure. The exposed data also included the industry, revenue, and employee count for each compromised organization.
Exceptional scale, poor opsec
Independent researcher Kevin Beaumont reported that “almost all” of the compromised devices remained online as of Wednesday morning. He went on to say that he has confirmed with multiple organizations found in the attackers’ logs that the credentials are real and current. In many cases, once the threat actors compromised the devices, they went on to access affected organizations’ centralized authentication systems, such as Radius servers and Microsoft Active Directory. The number of compromised devices comprises roughly half of all Internet-facing Fortinet firewalls, based on polling from Shodan.
Read full article
Comments
More From This Topic
View Topic
Parnell Square trial: Doctor on scene describes knife injuries inflicted on child
Riad Bouchaker (52), of no fixed address, is on trial at the Central Criminal Court charged with the …
Trump’s Iran Agreement Draws More Alarm Than Relief From GOP
Even before the White House released the actual text of its agreement with Iran on Wednesday, leaked …
Live updates: Trump signs interim agreement to end Iran war
President Donald Trump and Iranian President Masoud Pezeshkian have signed an initial agreement to e …
Why Trump is sabotaging his own nominee
President Donald Trump attends a press conference during the G7 Leaders' Summit in Evian-les-Bains, …
Want a deal on a heat pump? Team up with your neighbors.
Last year, Marie Tai needed abetter way to keep her condo cool. Her window air-conditioning units we …
Can open-source beat OpenAI?
As the U.S. and China battle for artificial intelligence supremacy, a fundamental divide in engineer …