Oracle, Comcast, Samsung and more have been caught up in a major breach of Fortinet devices which has seen security experts decry “everyman” access to GPU compute as a cybersecurity faultline.
Dubbed “Fortibleed”, the credential-harvesting campaign targeted around 74,000 FortiGate devices from more than 21,000 IP addresses in over 190 countries, leading to the leak of thousands of enterprise-level sign-in details. According to security researcher Kevin Beaumont, the attack surface represents almost half of all Fortinet firewall devices exposed to the public web.
The alarm was initially sounded by researcher Volodymyr Diachenko, with further analysis from Hudson Rock revealing targeted sectors included telecom, IT services, and financial institutions. Besides the likes of Oracle, other organizations affected include Foxconn, Siemens, PwC, and Accenture, as well as prominent government agencies - including a NATO defense contractor - and critical infrastructure providers.
According to Hudson Rock, the operation was achieved through the use of a 45-GPU cluster to process stolen password data. With this computing power, the group was able to analyze credential patterns every time the cluster successfully cracked one password, helping to generate variants for other accounts at scale.
Criminal teens and cyber Beans
While the process may point to the perils of future AI-driven automation helping trackers with even greater subterfuge, Beaumont argued the greater threat was from the democratization of GPU access in the wake of the AI wave, or, as he termed it, the “drunk GenAI (generative AI) stupidity gripping organizations worldwide.”
“Getting a 36 Nvidia GPU cluster a few years ago would have required talking to providers, getting racks, and lots of setup. Now? Get a VISA card, rent by the hour, and log in a few minutes later,” Beaumont said.
According to Diachenko, the list of leaked passwords was discovered via an exposed server, suggesting the attackers suffered from security gaps of their own. This led Beaumont to conclude the operation suggested “less nation state and more Advanced Persistent Teenagers. There’s a financial motivation — you spend money on renting GPUs to crack passwords to make money from intrusions and blackmail of corporate victims.
“Generative AI craze has lowered the bar so Mr Bean can crack passwords quickly using his mum’s credit card. Thanks, Sam Altman,” he added.
In response to the attack, Fortinet advised users to terminate all administrator and VPN sessions and reset credentials; implement multi-factor authorization on all administrator and VPN user accounts; upgrade software to the latest versions; validate configuration and check activity logs; and restrict external management of devices, particularly recommending removing internet administration altogether.
While the security firm claimed the attack reused credentials from previous security incidents, Beaumont disputed this assertion by pointing to new passwords observed in the data haul.
Beaumont also took a further jab at the AI craze by reminding readers that the Fortibleed attack was unearthed by the efforts of human beings as opposed to the recent automated and headline-grabbing efforts of Anthropic and OpenAI.
“As always, it will be people who get organisations out of danger – you can take your AI agents and stick them up your bum when shit’s on fire,” Beaumont argued.
Comments