Massive breach spills credentials for thousands of sensitive networks
来源:Ars Technica · 作者:Dan Goodin · · 分类:TechnologyResearchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself.
Nearly 74,000 Fortinet devices from more than 21,000 IP addresses in 194 countries have been compromised and their plaintext credentials exposed online, Bob Diachenko, a security researcher and head of SecurityDiscovery.com, said online and in an interview. He said he found the data after gaining access to the attackers’ command-and-control server and other infrastructure. The exposed data also included the industry, revenue, and employee count for each compromised organization.
Exceptional scale, poor opsec
Independent researcher Kevin Beaumont reported that “almost all” of the compromised devices remained online as of Wednesday morning. He went on to say that he has confirmed with multiple organizations found in the attackers’ logs that the credentials are real and current. In many cases, once the threat actors compromised the devices, they went on to access affected organizations’ centralized authentication systems, such as Radius servers and Microsoft Active Directory. The number of compromised devices comprises roughly half of all Internet-facing Fortinet firewalls, based on polling from Shodan.
Read full article
Comments
原文链接:https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks/More From This Topic
View Topic
1Password Acquires Apono in Reported $250M-$300M Deal
Apono specializes in just-in-time access governance technology for humans, machines, and AI agents.T …
Chi-Hua Chien saw Facebook coming — now he says the real AI winners won’t be selling AI
来源:TechCrunch · 作者:Connie Loizos · Wed, 17 Ju· 分类:TechnologyChi-Hua Chien has spent more than two de …
Roelof Botha joins SpaceX’s board of directors
来源:TechCrunch · 作者:Sean O'Kane · Wed, 17 Ju· 分类:TechnologyThe former Sequoia Capital leader is filli …
The Gemini-Powered Google Home Speaker Is Finally Here
来源:Wired · 作者:Julian Chokkattu · Wed, 17 Ju· 分类:TechnologyArriving six years after Google’s last sma …
“The View” exposes the big flaw in JD Vance’s act
For years, the MAGA universe has treated ABC’s “The View” as the ultimate cultural bogeyman — a dayt …
Roelof Botha joins SpaceX’s board of directors
来源:TechCrunch · 作者:Sean O'Kane · Wed, 17 Ju· 分类:TechnologyThe former Sequoia Capital leader is filli …