Solutions HKCERT urges all organisations using Fortinet firewalls and VPN-related devices to review their risk exposure immediately. Organisations may also check whether their domain appears in the relevant dataset through the following website to assess whether they may be affected by the data leakage incident: https://www.hudsonrock.com/fortinet HKCERT recommends that organisations take the following actions: Check immediately whether their organisation’s domain(s) appears on the affected list via the above website Change the passwords of all Fortinet administrator accounts and VPN accounts immediately Check whether the same passwords have been reused on other systems and change them as appropriate Enable multi-factor authentication for all administrative and remote access accounts Review login records, audit logs and configuration change records for any abnormal activity Avoid exposing management interfaces directly to the Internet, and restrict administrative access by IP allowlisting or other access control measures Activate incident response procedures immediately if any unauthorised access is suspected If an organisation suspects that data relating to its Fortinet devices has been exposed, it should immediately: Change the passwords of all relevant administrator, VPN and privileged accounts Invalidate existing login sessions and rotate any potentially affected credentials Check for abnormal logins, newly created accounts, or unauthorised configuration changes Isolate affected devices where necessary, and investigate whether the internal network has been compromised Preserve relevant logs and evidence for further analysis and reporting Businesses or members of the public who wish to report to HKCERT on information security related incidents such as malware, phishing, denial of service attacks, etc. can do so by completing the online form at: https://www.hkcert.org/incident-reporting , or calling the 24-hour hotline at +852 8105 6060. For further enquiries, please contact HKCERT at hkcert@hkcert.org .
The FortiBleed incident involves a credential leak from over 70,000 Fortinet devices, exposing administrative and VPN credentials. The article does not specify a CVE, CVSS score, affected version ranges, or a fixed software version. It urgently recommends organizations check the Hudson Rock website for exposure, immediately rotate all Fortinet-related credentials, enable multi-factor authentication, and restrict administrative interface access.