Cyber Security News

Threat Actor Claims to Have Unauthorized Fortinet VPN Access to 50+ Organizations

A threat actor has claimed to possess unauthorized access to Fortinet VPNs of over 50 organizations in the United States.

The alarming announcement was made via a post on the dark web, where the cybercriminal offers this illicit access for a hefty price of $7,500.

The news has sent shockwaves through the cybersecurity community, raising concerns about the vulnerabilities in widely-used security systems.

RDP Access and Admin Privileges Compromise

The threat actor’s claims don’t stop at VPN access; they also state that they have Remote Desktop Protocol (RDP) access and administrative privileges to some of the compromised organizations.

Join our free webinar to learn about combating slow DDoS attacks, a major threat today.

This access level could allow the attacker to execute commands, install malware, and exfiltrate sensitive data, posing a significant risk to the affected entities.

The sale of such access on the dark web demonstrates the increasing sophistication and boldness of cybercriminals.

Organizations that use Fortinet VPNs for secure remote access need to review their security protocols right away.

Cybersecurity experts recommend conducting thorough audits of VPN configurations, enforcing multi-factor authentication, and monitoring network traffic for unusual activities.

Additionally, organizations should stay informed about the latest threat intelligence and ensure that their systems are patched and up-to-date.

This incident underscores the critical need for robust cybersecurity measures and the importance of proactive threat detection and response strategies.

As cyber threats continue to evolve, organizations must remain vigilant and adaptive to safeguard their digital assets and maintain the trust of their stakeholders.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago