Massive breach spills credentials for thousands of sensitive networks
The affected include Oracle, Lenovo, FedEx, a NATO contractor, and Fortinet.
Signal weather
Rising
Momentum is building quickly, so this card is a good early entry point into the topic.
Researchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself. Nearly 74,000 Fortinet devices from more than 21,000 IP addresses in 194 countries have been compromised and their plaintext credentials exposed online, Bob Diachenko, a security researcher and head of SecurityDiscovery.com, said online and in an interview. He said he found the data after gaining access to the attackers’ command-and-control server and other infrastructure. The exposed data also included the industry, revenue, and employee count for each compromised organization. Exceptional scale, poor opsec Independent researcher Kevin Beaumont reported that “almost all” of the compromised devices remained online as of Wednesday morning. He went on to say that he has confirmed with multiple organizations found in the attackers’ logs that the credentials are real and current. In many cases, once the threat actors compromised the devices, they went on to access affected organizations’ centralized authentication systems, such as Radius servers and Microsoft Active Directory. The number of compromised devices comprises roughly half of all Internet-facing Fortinet firewalls, based on polling from Shodan. Read full article Comments
Stay on the signal
Follow Massive breach spills credentials for thousands of sensitive networks
Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.
Story map
Understand this topic fast
A quick entry into the story: why it matters now, who is involved, and where to go next for context.
Why it matters now
Topic constellation
Open the live map for this story
See which entities, story threads, sources, and follow-up articles shape this story right now.
Click nodes to continue
Entity pages
Story timeline
Continue with this story
A short sequence of events and follow-up stories to understand the arc quickly.
How reliable this looks
Signal and trust for Ars Technica
This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.
Reliability
92
Freshness
100
Sources in storyline
4
Related articles
More stories that share tags, source, or category context.
Oracle, Samsung, Siemens и госструктуры. Хакеры взломали почти 74000 устройств Fortinet в 194 странах
Ключ под ковриком – вкратце, как тысячи компаний из списка Fortune 500 «защищали» свои корпоративные сети.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
0day в Oracle PeopleSoft позволила хакерам обчистить более сотни организаций
Компания предлагает срочно закрывать серверы от хакеров вручную, потому что нормального исправления ещё нет.
Signal weather
The story has moved beyond the first headline and now acts as a reliable context anchor.
Why now
This story is still moving and pulling follow-up coverage.
Oracle warns of security bug that hackers abused to breach 100+ companies
The tech giant warned of a security flaw that a cybercrime gang said it's exploiting as part of a mass-hacking campaign. Google said it notified more than 100 organizations that...
Signal weather
The story has moved beyond the first headline and now acts as a reliable context anchor.
Why now
This story is still moving and pulling follow-up coverage.
Access OpenAI models and Codex through your Oracle cloud commitment
Access OpenAI models and Codex through Oracle Cloud, using existing commitments to build and deploy AI with enterprise security and governance.
Signal weather
The story has moved beyond the first headline and now acts as a reliable context anchor.
Why now
This story is still moving and pulling follow-up coverage.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
Rocket Report: Rebuild begins at Blue Origin launch pad; Relativity targets Mars
A French launch startup is scrapping the name of its rocket, apparently due to a trademark issue.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
As global warming threatens corals, scientists search for reefs that can take the heat
Researchers say these coral strongholds may help repopulate more degraded reefs.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
A bold satellite rescue mission came together in record time, but will it work?
"I consider this a success already, just from the fact that we're even going to try this."
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Microsoft discovers new lightweight backdoor that steals cryptocurrency
Crypto Clipper spreads over USB and communicates over Tor.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.