Massive breach spills credentials for thousands of sensitive networks
来源:Ars Technica · 作者:Dan Goodin · · 分类:TechnologyResearchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself.
Nearly 74,000 Fortinet devices from more than 21,000 IP addresses in 194 countries have been compromised and their plaintext credentials exposed online, Bob Diachenko, a security researcher and head of SecurityDiscovery.com, said online and in an interview. He said he found the data after gaining access to the attackers’ command-and-control server and other infrastructure. The exposed data also included the industry, revenue, and employee count for each compromised organization.
Exceptional scale, poor opsec
Independent researcher Kevin Beaumont reported that “almost all” of the compromised devices remained online as of Wednesday morning. He went on to say that he has confirmed with multiple organizations found in the attackers’ logs that the credentials are real and current. In many cases, once the threat actors compromised the devices, they went on to access affected organizations’ centralized authentication systems, such as Radius servers and Microsoft Active Directory. The number of compromised devices comprises roughly half of all Internet-facing Fortinet firewalls, based on polling from Shodan.
Read full article
Comments
原文链接:https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks/More From This Topic
View Topic
Caleb Yirenkyi aparece al 95' y le da el triunfo a Ghana frente a Panamá
En tiempo de compensación, Caleb Yirenkyi definió dentro del área tras una asistencia del número 10 …
Carvana Is Turning Dealerships Into 'Playgrounds,' Test-Drive Centers With Sales All Online
来源:Slashdot · 作者:BeauHD · 2026-06-17· 分类:TechnologyCarvana is testing a radically different new-car …
Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization
来源:The Hacker News · 作者:[email protected] (The Hacker News) · Wed, 17 Ju· 分类:CybersecurityFor s …
Google to use UK and EU user IP addresses for ad personalization
来源:Bleeping Computer · 作者:Ax Sharma · Wed, 17 Ju· 分类:CybersecurityFrom August 3, 2026, Google will u …
Privacy own-goal: World Cup blunder leaks Lionel Messi’s passport details
Argentina's World Cup squad had their passport numbers leaked before a ball was kicked - not by hack …
What’s at Stake If Indonesia Loses Its Emerging Market Status
来源:Bloomberg · 作者:Abhishek Vishnoi, Prima Wirayani · Thu, 18 Ju· 分类:FinanceStock market information …