CyberSecurity SEE

FBI Warns: FortiBleed Attackers Can Lock Organizations Out of Firewalls

FBI Warns: FortiBleed Attackers Can Lock Organizations Out of Firewalls

Cybersecurity Threats: Evolving Tactics and FBI Guidance

In an alarming update for businesses and organizations relying on digital infrastructure, the FBI has shed light on recent cybersecurity threats, particularly regarding unauthorized account creation during security breaches. Attackers have been observed exploiting vulnerabilities by creating new accounts that were previously nonexistent on compromised devices. This tactic not only enables them to establish footholds within the network but also facilitates lateral movement across various organizational systems. In some cases, attackers have gone as far as deleting existing accounts, making it increasingly difficult for organizations to maintain persistent access and responses to the intrusions.

Ben Bernstein, a notable cybersecurity advisor and manager of the cybersecurity advisors team at Huntress, emphasized the severity of such attacks. “When you no longer have access to your own firewall, you cannot just apply a software patch and move on,” he explained. This emphasizes a crucial point: once the attackers have gained control, the standard procedures for addressing vulnerabilities become virtually ineffective. Bernstein highlighted that adversaries are well aware that organizations will be compelled to perform a physical factory reset and a complete rebuild of their hardware systems before they can begin to address the ensuing complications brought on by encryption locks put in place by the attackers.

As organizations scramble to fortify their defenses against these evolving tactics, the FBI’s recently published information regarding account names and infrastructure indicators is poised to become a vital resource. It serves as a call to action for businesses to proactively investigate any signs of compromise within their systems. The agency has recommended a series of investigative actions, including thorough reviews of Fortinet accounts and configurations to identify any unauthorized alterations made during breaches.

In addition to examining account configurations, organizations are urged to meticulously analyze logs from firewalls, VPNs, authentication services, and domain controllers for any suspicious activities that may signify an ongoing breach. A specific emphasis was placed on scrutinizing REST API keys that are either unknown or unexpected. Such API keys could potentially grant attackers automated access to FortiGate systems, amplifying the risks posed by the breach.

Furthermore, the FBI has provided a set of actionable recommendations to enhance security protocols. Among these recommendations is the immediate termination of all active administrative and VPN sessions. This step is critical in halting any ongoing unauthorized access, thereby minimizing the scope of the intrusion. Organizations are also advised to reset both the Fortinet administrative and VPN credentials as a preventive measure against further unauthorized access.

To bolster protection against future breaches, the adoption of phishing-resistant Multi-Factor Authentication (MFA) is strongly recommended. This security layer adds an additional barrier for any would-be intruders attempting to gain access through compromised credentials. Coupled with this, leveraging PBKDF2—a robust key derivation function—when setting up administrator credentials significantly reduces the risk of credential theft and subsequent unauthorized access.

In light of the increasing sophistication of cyber threats, organizations must remain vigilant and proactive. The FBI’s guidance not only helps in identifying current vulnerabilities but also acts as a crucial reminder of the ever-dynamic landscape of cybersecurity risks. As attackers continue to refine their methods, the importance of layered security strategies and swift responses to potential threats cannot be overstated.

By systematically implementing the FBI’s recommended actions and continuously monitoring for signs of compromise, organizations can mitigate the risks posed by these cyber adversaries. This proactive stance not only protects their assets but additionally fortifies the broader cybersecurity ecosystem, making it more resilient against future threats.

In summary, the interplay of evolving cyberattack tactics and the defensive measures outlined by the FBI paints a sobering yet essential picture of the current cybersecurity landscape. Organizations that take these threats seriously and act promptly will not only safeguard their own infrastructures but also contribute to a more secure digital environment for all stakeholders involved.

Source link

Exit mobile version