[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVBLJTp7qwgFeaI8CST1eXN7odMQEe6r0JRu5qTIWaJ8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"ae23585e-6a01-4be6-b7bb-bb4e4d45ba48","russian-iab-exploits-unpatched-fortigate-devices-to-harvest-110m-credentials","e62d812b-7e78-403f-a551-e958efa2a0ed","Russian IAB Exploits Unpatched FortiGate Devices to Harvest 110M+ Credentials","A Russian initial access broker has been systematically exploiting unpatched FortiGate firewalls since at least February, leveraging custom tools to sniff and crack over 110 million credentials from more than 430,000 devices. The root cause is a failure to apply critical patches to internet-facing network appliances in a timely manner, leaving a massive attack surface exposed to well-resourced adversaries. The scale of credential harvesting means entire identity infrastructures — including VPN accounts, authentication tokens, and privileged access credentials — may be compromised across victim organizations. The confirmed breach of a NATO-aligned defense contractor underscores that the consequences extend beyond individual organizations into national security and supply chain integrity.","**Immediate actions:**\n- Apply all available FortiGate firmware patches immediately and verify patch status across every internet-facing appliance in your inventory.\n- Force a full credential reset for all accounts that authenticate through FortiGate VPNs or any potentially affected network devices.\n- Isolate any FortiGate devices that cannot be immediately patched by placing them behind additional network controls or taking them offline.\n\n**Detection measures:**\n- Deploy network traffic monitoring to detect anomalous credential harvesting or lateral movement patterns originating from perimeter devices.\n- Review firewall and VPN logs for signs of FortigateSniffer-style packet capture activity or unusual authentication bursts.\n- Enroll all FortiGate management interfaces in continuous vulnerability scanning tied to real-time CVE feeds.\n\n**Long-term improvements:**\n- Implement a formal patch SLA policy requiring critical patches on internet-facing infrastructure to be applied within 24–72 hours of release.\n- Enforce multi-factor authentication (MFA) on all VPN and remote access entry points to limit the impact of harvested credentials.\n- Maintain a continuously updated asset inventory of all network appliances and segment critical systems to limit lateral movement in the event of a perimeter breach.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 6: Access Control Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 IA-5: Authenticator Management","NIST CSF ID.AM-1: Asset Inventory","NIST CSF RS.MI-3: Vulnerability Mitigation","ITIL Change Management: Emergency Change Procedures","ISO\u002FIEC 27001 A.12.6.1: Management of Technical Vulnerabilities","ISO\u002FIEC 27001 A.9.4.2: Secure Log-on Procedures","GDPR Article 32: Security of Processing (credential exposure risk)","published","2026-06-23T12:21:16.174987+00:00","2026-06-23T12:21:15.836+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.securityweek.com\u002Frussian-initial-access-broker-behind-fortibleed-campaign\u002F","russian-initial-access-broker-behind-fortibleed-campaign-93f9ff","Russian Initial Access Broker Behind FortiBleed Campaign",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":45,"name":46,"slug":47,"description":48,"color":49},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[51],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"9664cc73-3883-4c15-87ee-df68acf818b1","2026-06-23","afternoon","ThreatNoir Afternoon Brief — June 23","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-23\u002Fthreatnoir-afternoon-brief-2026-06-23.mp3"]