Fortibleed Digest: Facts and Action Items

Fortibleed word against ochre coloured background

This article is intended to give you the high-level, non-technical information you need to check your organisation’s exposure and respond. If your organisation does not use Fortinet products, you can stop reading here. If it does, keep reading.

What is Fortibleed?

Fortibleed is not a vulnerability within the Fortinet products below, so patching does not completely mitigate the risks. Fortibleed is a credential harvesting campaign run by the threat actor Lynx/ INC targeting these products:

What does it do?

The campaign has two parts:

What do you need to do?

Security patches alone do not fully mitigate this campaign. While you should ensure you are running the latest versions of your Fortinet services, other actions are required:

Fortinet recommends the following:

Additional security best practices for administrator access and general hardening can be found in the Best Practices Guides.

If there is any evidence of unapproved modification of the configuration or other IoCs:

For more in-depth analysis, refer to the following reports:

Categories: