Hook
More breakout videos from this creator.
Half of all the Fortinet firewalls on the internet just got owned. And most of the people running them probably don't know yet. Fortinet makes the firewalls and VPN gateways that sit at the edge of company networks, hospitals, banks, governments. If data flows in or out, there's a good chance a Fortinet device is checking it. Well, this month researchers found a data set circulating online. It contained verified working admin credentials for somewhere between 73,000 and 86,000 of those devices across 194 countries. This has been called FortiBleed. Here's how it works. So an attacker scan the internet for Fortinet devices and then they threw billions of previously leaked passwords at them automatically. And when they got in, because eventually they did, they use the device to harvest even more credentials that are passing through. The whole thing is this wonderful self-sufficient, self-sustaining beast. But this part, this is the interesting bit. Researchers found 25 character passwords in the data set. Complex ones, symbols, numbers, mixed case, completely useless because the attackers weren't guessing passwords, they were stealing them. And some organisations that actually patched the vulnerability are still at risk because the patch only works if an admin locks in afterwards to force a rehash of the stored credentials. If they didn't do that, the old vulnerable hashes are just sat there. To put this into scale, the last major Fortinet credential leak in 2022 hit around 15,000 devices. So FortiBleed, this one, is five to six times bigger. If your organisation uses Fortinet, you need to be asking your IT team right now whether you're in that data set. There is a checker tool available. I'll try and put the link somewhere if I can work it out. So have a look around for the link. If not, Google it and avoid the sponsored links, cause bad things happen in the sponsored links. Follow for more.