ASD issues critical alert for Fortinet credential exposure

By Joshua Gliddon on Jun 19, 2026 1:39PM
ASD issues critical alert for Fortinet credential exposure

The Australian Signals Directorate’s (ASD) Australian Cyber Security Centre (ACSC) has issued a critical alert regarding a widespread malicious campaign against Fortinet Firewalls and VPN gateways.

The campaign largely utilises exposed credentials and credential-based attacks, leading to potential compromise and further credential exposure.

Leveraging these credentials could enable malicious actor’s remote access to the devices and connected networks, as well as allow changes to various settings, including security controls.

ASD's ACSC has advised all organisations that use Fortinet Firewall or VPN services to rotate credentials, stating that all admin and VPN credentials should be rotated immediately, as well as ensuring devices are patched to prevent attackers from exploiting existing vulnerabilities in older firmware.

Organisations are also advised to restrict management interface exposure to reduce the attack surface of Fortinet infrastructure, ensuring firewall admin/management interfaces are not internet accessible unless necessary, plus enforcing Multi-Factor Authentication for all external interfaces to minimise the impact of stolen credentials.

Ensuring credentials are being stored with PBKDF2 hashing to prevent the offline brute forcing of credentials, with all admin accounts logged back into once devices are fully updated to force the encryption to change to PBKDF2, and examining logging for malicious activity, reviewing authentication logs and access logs and investigating abnormal logins or changes, also forms part of the ASD's advice.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © nextmedia Pty Ltd. All rights reserved.

Add techpartner.news as your trusted source

Tags:

Log in

Email:
Password:
  |  Forgot your password?