Trusence Every claim has a source
Last updated 8 October 2026 Search Türkçe
← All stories
Security

FBI says FortiBleed attacks are still locking out FortiGate VPN admins

The agency says some victims need more than patches and password resets to get control of their firewalls back.

The FBI says FortiBleed activity is still hitting exposed Fortinet FortiGate firewalls and SSL VPN gateways, where attackers use stolen credentials to get in and lock out legitimate admins. The agency says the attack chain can start with leaked or stuffed passwords, then move to theft of more authentication data, offline cracking of password hashes, and in some cases the creation of rogue administrator accounts. The FBI also says some incidents have used those admin rights to remove existing admins or change their passwords, which cuts victims off from their own devices. It warns that fixing the problem may take more than patching and password resets, and recommends limiting outside access, ending VPN sessions, turning on MFA, checking logs, and using PBKDF2 for admin password storage instead of legacy SHA-256.

Why it matters

For organisations running exposed FortiGate firewalls and SSL VPN gateways, the issue is not just intrusion but loss of administrative control. Once attackers get in with stolen credentials and reset or remove admins, the normal recovery steps may not be enough. The FBI’s guidance points to tighter external access, live session cleanup, MFA and log review as part of restoring trust in the device.

Sources

  • BleepingComputer