FBI: FortiBleed attackers can lock organizations out of their own firewalls | #cybercrime | #infosec


During an intrusion, attackers create new accounts that were not previously present on the device. In some cases, they then delete existing accounts, preventing organizational persistence and attempting to move laterally through the environment.

“When you no longer have access to your own firewall, you cannot just apply a software patch and move on,” said Ben Bernstein, manager, cybersecurity advisors team at Huntress. “These attackers know organizations will have to physically factory reset and rebuild the hardware before the encryption starts.”

FBI’s newly published account names and infrastructure indicators can help organizations investigate potential compromise. The agency recommended reviewing Fortinet accounts and configurations for unauthorized changes, checking firewall, VPN, authentication, and domain controller logs for suspicious activity, and looking for unknown or unexpected REST API keys that could provide attackers with automated access to FortiGate systems.

Terminating active administrative and VPN sessions, resetting Fortinet administrative and VPN credentials, enforcing phishing-resistant MFA, and using PBKDF2 for admin credentials were also recommended.



Click Here For The Original Source.

——————————————————–

..........

.

.