FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices
What Happened — The FBI’s latest advisory confirms that threat actors are still exploiting the FortiBleed vulnerability (CVE‑2022‑42475) in Fortinet FortiGate firewalls. SOCRadar’s telemetry shows more than 86,644 devices across 194 organizations have been compromised, with attackers using an unauthenticated remote‑code‑execution path to install persistent back‑doors.
Why It Matters for Trust & Control Assurance
- Continuous vulnerability‑management programs must surface unpatched CVEs in real time and produce auditable evidence of remediation.
- Demonstrable, time‑stamped patch‑deployment records satisfy the control objective of “Vulnerability Management” that underpins many frameworks (e.g., NIST CSF Identify, ISO 27001 A.12.6).
- A robust Trust Center can aggregate patch‑status data across firewalls, giving auditors a defensible trail of due‑diligence.
Who Is Affected – Telecommunications, financial services, healthcare, and any sector that relies on FortiGate perimeter appliances for network security.
Recommended Actions
- Inventory all FortiGate devices and verify firmware versions against Fortinet’s patch list.
- Apply the latest FortiOS updates (≥ 7.2.4 or later) that address CVE‑2022‑42475.
- Enable automated vulnerability scanning and integrate findings into your continuous control‑monitoring platform.
- Capture patch‑deployment logs as evidence for audit readiness.
Technical Notes – The exploit works over TCP 443, bypasses authentication, and allows arbitrary code execution on the firewall’s management plane. No specific data set was disclosed, but compromised devices can be leveraged to intercept traffic or exfiltrate data.
Source: HackRead – FBI Warns FortiBleed Campaign Still Active