La campagne FortiBleed liée aux groupes de ransomware INC et Lynx

15 sources
  • SOCRadar a lié la campagne FortiBleed aux groupes de ransomware INC Ransom et Lynx après avoir trouvé un opérateur actif sur les panneaux de négociation des deux groupes.
  • L'opération a ciblé plus de 430 000 pare-feu Fortinet dans le monde, récoltant plus de 110 millions d'identifiants et entraînant au moins 12 déploiements de ransomware.
  • Les attaquants possèdent également une vulnérabilité zero-day Nextcloud et ont constitué des listes de cibles pour les environnements Citrix, selon SOCRadar, ce qui laisse présager une extension de la campagne.
Sources (15)
  1. 1 FortiBleed Credential Theft Linked to INC and Lynx Ransomware ... thehackernews.com
  2. 2 FortiBleed credential-theft campaign linked to Lynx ransomware www.bleepingcomputer.com
  3. 3 Russian Initial Access Broker Behind FortiBleed Campaign www.securityweek.com
  4. 4 SOCRadar Links FortiBleed Campaign to INC and Lynx ... itnerd.blog
  5. 5 CISA urges device hardening after thousands of Fortinet credentials ... www.cybersecuritydive.com
  6. 6 Active FortiBleed Campaign Impacting Fortinet Devices Across 194 ... arcticwolf.com
  7. 7 FortiBleed linked to ransomware groups INC and Lynx www.techzine.eu
  8. 8 FortiBleed – New SOCRadar In-Depth Technical Analysis Published itnerd.blog
  9. 9 CISA Urges Quick Patching of Fortinet Vulnerability Amid ... - Reddit www.reddit.com
  10. 10 FortiGate credentials are now the attack path. CISA is urging Fortinet ... www.facebook.com
  11. 11 What Is FortiBleed? Fortinet Credential Theft Campaign Explained socradar.io
  12. 12 FortiBleed: 86,644 Firewalls Compromised — Is Your Las Vegas ... cmitsolutions.com
  13. 13 FortiBleed Attack 2026: CISA Warns on 74,000 Devices blog.cybernexora.com
  14. 14 FortiBleed exposes Fortinet credentials at global scale - Field Effect fieldeffect.com
  15. 15 The Rise of Credential Compromise Attacks - Fortinet www.fortinet.com

Laisser un commentaire