10/07/2026 | News release | Distributed by Public on 10/07/2026 14:16
The FBI and Secret Service released an advisory Oct. 6 warning of ongoing activities by FortiBleed, a global credential-compromise campaign used by threat actors to target internet-facing Fortinet FortiGate firewalls and virtual private network gateways at critical infrastructure organizations. The agencies said the campaign exploits reused or leaked credentials and legacy password storages, allowing threat actors to harvest and decode authentication data at scale. Impacted organizations could be locked out of their systems if threat actors disable accounts or change passwords and would require remediation actions beyond typical patching and password resets. The advisory includes indicators of compromise and mitigation actions to defend against potential attacks.
For more information on this or other cyber and risk issues, contact John Riggi, AHA national advisor for cybersecurity and risk, at [email protected], or Scott Gee, AHA deputy national advisor for cybersecurity and risk, at [email protected]. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.