FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
The FBI has issued a warning that attacks exploiting Fortinet FortiGate firewalls and SSL VPN gateways are still active, with threat actors locking legitimate administrators out of their own systems.
Why this matters: Getting locked out of your own firewall is not a minor inconvenience. It means attackers have enough control to block the people responsible for stopping them. Organizations running FortiGate devices need to treat this as an active threat, not a patching reminder. If your VPN gateway is exposed to the internet and not updated, someone else may already be in the chair. The FBI warning means this is not theoretical — it is happening now, at scale.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.