Urgences 24 sur 7 – (888) 287-5858   Connexion au Portail TitanSupport    Contactez-nous      Blogue

Security Advisory: Fortinet Firewall Hack - Cover PhotoRecent events have highlighted a critical security disclosure involving Fortinet devices. A hacker group known as “Belsen Group” has leaked sensitive data allegedly associated with approximately 15,000 Fortinet firewalls. The leaked information includes highly sensitive details such as plaintext credentials, firewall configurations, and management certificates, raising significant concerns about the potential for unauthorized access and exploitation.

This incident not only underscores the importance of timely patching and proactive security measures but also serves as a stark reminder of the evolving sophistication of cyber threats. Organizations must prioritize robust monitoring and incident response capabilities to mitigate such risks and protect their assets. 

 

What Happened? 

Leaked Data
The attackers claim to have leaked IP addresses, plaintext credentials, and configurations from affected devices. Security researcher Kevin Beaumont has verified the authenticity of this information, which includes usernames, passwords, device management certificates, and firewall rules. 

Vulnerability Details
The breach leverages CVE-2022-40684, a zero-day vulnerability disclosed in October 2022. Following its disclosure, a proof-of-concept exploit became widely available, leading to an increase in exploitation activities. Despite Fortinet’s urgent patching advisory, some devices remained unpatched, leaving them vulnerable to attacks. 

Potential Impact
Although the leaked data is from 2022, unpatched systems, unchanged credentials, or misconfigured firewalls may still expose organizations to risk. Attackers could leverage the leaked information to compromise systems or establish persistent access. 

 

How GoSecure Is Responding 

At GoSecure, our team is: 

  • Monitoring Threat Intelligence: Continuously cross-referencing leaked IPs and credentials with our Managed Detection and Response (MXDR) platform to identify potential threats. 
  • Collaborating with Authorities: Working alongside security authorities and Fortinet to gather updates and provide actionable insights to our clients. 
  • Threat Hunting: Actively searching for indicators of compromise (IoCs) across client environments and escalating findings for immediate action. 

 

Recommendations for Fortinet Users 

To mitigate risk, we recommend taking the following steps: 

Patch Your Systems
Ensure all Fortinet devices are running the latest firmware and security updates. CVE-2022-40684 has been patched, and updates should be applied without delay. 

Change Credentials
Update all login credentials for Fortinet devices. If credentials have not been updated since October 2022, consider them compromised. 

Review Configurations
Audit your firewall configurations to confirm no unauthorized changes have been made and that all rules align with your organization’s security policies. 

Enable Continuous Monitoring
Set up robust monitoring of your Fortinet logs to detect suspicious activity. This is where advanced Managed Detection and Response services can make a difference. 

Engage in Threat Hunting
Initiate internal incident response processes and threat-hunting activities to detect any persistence mechanisms or malicious activity within your network. 

 

GoSecure Can Help 

It’s more important than ever to have proactive defenses in place. GoSecure Titan® Managed Extended Detection & Response (MXDR) provides 24×7 monitoring, enabling us to ingest logs from your Fortinet devices into our SIEM to detect and mitigate threats in real time. Additionally, our GoSecure Titan® Managed Perimeter Defense (MPD) ensures your firewalls are always updated and optimized to protect against emerging vulnerabilities. 

 

Next Steps 

Our team is committed to keeping you informed as more information becomes available. If you would like assistance in securing your environment or implementing proactive measures, contact us today to learn how GoSecure’s services can enhance your organization’s security posture. 

Learn More about GoSecure MXDR 

Détection et réponse gérées et étendues GoSecure TitanMC (MXDR)

Détection et réponse gérées et étendues GoSecure TitanMC (MXDR) Fondation

Gestion des vulnérabilités en tant que service GoSecure TitanMC (VMaaS)

Surveillance des événements liés aux informations de sécurité gérée GoSecure TitanMC (SIEM gérée)

Défense du périmètre gérée GoSecure TitanMC (pare-feu)

Détection et réponse des boîtes de messagerie GoSecure TitanMC (IDR)

Passerelle de messagerie sécurisée GoSecure TitanMC (SEG)

Modélisateur de menaces GoSecure TitanMC

Identity GoSecure TitanMC

Plateforme GoSecure TitanMC

Services de sécurité professionnels de GoSecure

Services de réponse aux incidents

Évaluation de la maturité de la sécurité

Services de confidentialité

Services PCI DSS

Services de piratage éthique

Opérations de sécurité

MicrosoftLogo

GoSecure MXDR pour Microsoft

Visibilité et réponse complètes au sein de votre environnement de sécurité Microsoft

CAS D'UTILISATION

Cyberrisques

Mesures de sécurité basées sur les risques

Sociétés de financement par capitaux propres

Prendre des décisions éclairées

Sécurité des données sensibles

Protéger les informations sensibles

Conformité en matière de cybersécurité

Respecter les obligations réglementaires

Cyberassurance

Une stratégie précieuse de gestion des risques

Rançongiciels

Combattre les rançongiciels grâce à une sécurité innovante

Attaques de type « zero-day »

Arrêter les exploits de type « zero-day » grâce à une protection avancée

Consolider, évoluer et prospérer

Prenez de l'avance et gagnez la course avec la Plateforme GoSecure TitanMC.

24/7 MXDR

Détection et réponse sur les terminaux GoSecure TitanMC (EDR)

Antivirus de nouvelle génération GoSecure TitanMC (NGAV)

Surveillance des événements liés aux informations de sécurité GoSecure TitanMC (SIEM)

Détection et réponse des boîtes de messagerie GoSecure TitanMC (IDR)

Intelligence GoSecure TitanMC

Notre SOC

Défense proactive, 24h/24, 7j/7

À PROPOS DE GOSECURE

GoSecure est un leader et un innovateur reconnu en matière de cybersécurité, pionnier de l'intégration de la détection des menaces au niveau des terminaux, du réseau et des courriels en un seul service de détection et réponse gérées et étendues (MXDR). Depuis plus de 20 ans, GoSecure aide ses clients à mieux comprendre leurs failles en matière de sécurité et à améliorer leurs risques organisationnels ainsi que leur maturité en matière de sécurité grâce aux solutions MXDR et aux services professionnels fournis par l'une des équipes les plus fiables et les plus compétentes de l'industrie.

CALENDRIER D’ÉVÉNEMENTS

No upcoming events.

DERNIER COMMUNIQUÉ DE PRESSE

AVIS DE SÉCURITÉ

Urgences 24 sur 7 – (888) 287-5858