
FortiBleed事件揭露:逾7萬台Fortinet設備憑證外洩
威脅情報平台InfoStealers揭露「FortiBleed」事件,指出超過7萬台Fortinet防火牆及SSL VPN設備登入憑證遭駭客竊取外洩。台灣資安署已發布警訊並通知相關單位採取防護措施,目前國內尚未接獲駭侵通報。

威脅情報平台InfoStealers揭露「FortiBleed」事件,指出超過7萬台Fortinet防火牆及SSL VPN設備登入憑證遭駭客竊取外洩。台灣資安署已發布警訊並通知相關單位採取防護措施,目前國內尚未接獲駭侵通報。

資安研究人員指出,一波大規模駭客攻擊行動鎖定Fortinet防火牆設備,已侵入全球知名機構,包括財星500大企業及逾15國政府機關,密碼可能遭竊。Hudson Rock公司追蹤此行動,發現約7萬5000台設備受影響,主要分布在美國、印度與台灣。

A massive breach of Fortinet firewalls has exposed nearly 74,000 devices globally, granting Russian-speaking attackers access to major organizations like Oracle, Chevron, and a NATO defense contractor. Researchers found plaintext credentials online, enabling lateral movement into critical systems like Active Directory.

Cybercriminals have compromised over 30,000 Fortinet firewalls and VPNs globally in a campaign dubbed FortiBleed. Hackers exploit weak or reused passwords to gain access, using compromised devices to steal more credentials and expand their reach. Major companies like Accenture, Comcast, and Samsung are among the victims.

Fortinet hat elf Sicherheitslücken in verschiedenen Produkten behoben, darunter zwei kritische und eine hochriskante Schwachstelle, die unbefugten Codeausführungen ermöglichen.

Police in Malaysia's Penang state have found that ethnic Indians are significantly less likely to fall for online scams compared to other racial groups. Only 7% of 5,090 scam cases reported in Penang last year involved Indian victims, despite scammers targeting all communities equally. Penang CCID deputy chief Pang Meng Tuck attributed this to Indians responding to scammers with a barrage of questions. The findings come as Malaysia removed over 98,500 scam-related posts in 2025, up from 63,652 in 2024.