top of page
Writer's pictureMegan Haybyrne

Attackers have leaked passwords for 500,000 Fortinet VPN accounts on RAMP hacking forum

Description

A threat actor known as 'Orange,' who is the administrator of the newly launched RAMP hacking forum and a previous operator of the Babuk Ransomware operation has leaked a list of around 500,000 Fortinet VPN login names and passwords on RAMP hacking forum for free, which were scraped from devices by exploiting path traversal (CVE-2018-13379) vulnerability. Attackers can use leaked VPN credentials to access a network to perform data exfiltration, install malware, and perform ransomware attacks.


Vulnerabilities:

CVE-2018-13379



Recommendation

Workaround:

It is recommended to reset all VPN user passwords and check logs for possible intrusions.



Reference URL:

  • https://www.bleepingcomputer.com/news/security/hackers-leak-passwords-for-500-000-fortinet-vpn-accounts/

  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13379




Recent Posts

See All

Testimonials

Ibec - For Irish Business

"Ibec engaged with VISO two years ago.  While our primary objective was to improve our information security posture, we were also looking for a long-term partner with expertise and knowledge of the continually evolving cyber landscape. The professionals at VISO are a pleasure to work with and their team is always on hand when we need them."

2-3 Prospect Road, Glasnevin, Dublin 9, D09 K5V2

​

​

Telephone: Ireland +353 1 9121331  U.K.  +44 20 30260575

 

We simplify Cyber Security 

​

Privacy Policy

  • Twitter
  • Facebook
  • LinkedIn

© 2022 proudly created by The Rainbow Vault

ISO 27001 Cyber Security standard_Awarded to VISO Cyber Security
cyberessentials_certification- awarded to VISO Cyber Security
bottom of page