Security Alert: If Your Work Uses Fortinet VPN, Ask Your IT Team About This Issue
Hackers obtained passwords to 74,000 business security devices. If you connect to work from home using a VPN, your company may need to take action.
Source
CISA
Original headline: CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
Plain-English summary by GetCyberRight. Read the full report at the source above.
CISA, the federal agency that protects computer networks, has warned about a widespread problem affecting business security devices made by Fortinet. Hackers have obtained login credentials (usernames and passwords) for approximately 74,000 devices, including VPN gateways that many people use to connect to their work networks from home. This problem is being called FortiBleed. Both government agencies and private companies are affected. This mainly affects people who connect to their workplace remotely using a VPN (virtual private network). If your employer uses Fortinet devices for remote access, the credentials you use to log in from home may have been compromised.
Hackers could potentially use these stolen credentials to access your company's network and the information stored there. If you work from home and use a VPN to connect to your office network, here is what to do right now:
- Contact your IT department or help desk immediately and ask if your company uses Fortinet devices.
- If they do, ask whether you need to change your VPN password or take any other security steps.
- Watch for any unusual emails claiming to be from your IT department. When in doubt, call them directly using a known phone number, not one from the email.
- Do not click links in emails about security updates unless you have verified them with your IT team first. For ongoing protection, make it a habit to use strong, unique passwords for your work accounts. Enable two-factor authentication whenever your company offers it. This adds an extra security step beyond just your password. Stay alert to messages from your IT department about security updates, and follow their instructions promptly. If something seems suspicious about your work computer or network connection, report it to your IT team immediately rather than ignoring it.
Curated from trusted cybersecurity sources by GetCyberRight
Source: CISAStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Why the Texas Parks Breach Matters Even If Your Bank Account Is Fine
A vendor breach exposed 3+ million driver's licenses. Here's why your data is valuable to criminals even when nothing gets stolen from your accounts right away.
3 min readApple's Hide My Email Feature Just Got Weaker. Here's What That Means.
Apple changed Hide My Email to let websites detect and block anonymous addresses, undermining a key privacy tool families rely on to protect their inboxes.
4 min read
Nearly 15,000 WordPress Sites Were Silently Infecting Visitors This Week
A global law enforcement operation just cleaned up infected websites that were compromising devices without any clicks or downloads required.
3 min read
FortiBleed: Why Enterprise Hacks Put Your Home Network at Risk
Over 86,000 compromised business firewalls now target everyday users. Here's what this enterprise breach means for your family's online safety.
3 min read