Signal//Noise #025 - Fortibleeder
86,644 Fortinet firewalls were breached, and patching the firmware did not stop it. Here is what happened and what to do now.
EPISODE OVERVIEW
FortiBleed is an active campaign that put verified, working logins for 86,644 Fortinet FortiGate firewalls across 194 countries into an attacker's database. The twist: a firmware update did not protect most victims, because the real weakness is reused, unrotated credentials. Chris Loehr and Bob Miller break down how the attack works, who is affected, and exactly what to do, then compare analysis from five AI tools (Claude, ChatGPT, Perplexity, Grok, and Gemini) as part of the Signal // Noise format.
WHAT WE COVER
- How FortiBleed turns reused passwords into a verified, self-reinforcing breach
- Why patched firewalls stayed exposed, and the legacy hash problem behind it
- The FortigateSniffer tool and how it wiretaps SSL VPN traffic
- Where CVE-2026-24858 fits, and why it is not the main story
- The real scope: telecom, government, banks, healthcare, and energy across 194 countries
- How five AI tools agreed, disagreed, and where one got the CVSS score wrong
- A step-by-step remediation plan for Fortinet operators
KEY TAKEAWAYS
- Patching is not the same as being safe; rotate credentials and force post-upgrade logins
- Treat any device in the FortiBleed dataset as a confirmed breach
- Turn on phishing-resistant MFA and get management interfaces off the public internet
- Hunt on behavior and suspicious accounts, since public network IOCs are limited
- Firewalls and VPN gateways are identity-bearing systems and need to be governed like one
ABOUT THE SHOW
Signal // Noise is a cybersecurity podcast where Chris Loehr and Bob Miller break down the latest security incidents, threats, and trends. Each episode runs the same incident through five leading AI analysis tools (Claude, ChatGPT, Perplexity, Grok, and Gemini) then compares results live on air. Subscribe for weekly analysis that helps security professionals and business leaders stay ahead of emerging threats.
RESOURCES
- Original article: https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/
- SOCRadar FortiBleed exposure checker: https://socradar.io/free-tools/fortibleed
- CISA hardening alert (June 18, 2026): https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
- Fortinet PSIRT response: https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices
- CVE-2026-24858 (NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-24858
TAGS
FortiBleed, Fortinet, FortiGate, VPN security, credential theft, data breach, cybersecurity, infosec, threat intelligence, CVE-2026-24858, SSL VPN, network security, AI analysis, ChatGPT, Claude AI, Gemini, Perplexity, Grok, CISO, IT security