BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Brute-Force Attacks Surge Against Fortinet SSL VPN Devices Globally

Brute-Force Attacks Surge Against Fortinet SSL VPNs, Signal Potential Security Vulnerabilities

  • Researchers report a sharp rise in brute-force attacks targeting Fortinet SSL VPN devices.
  • Over 780 unique IP addresses were involved in the attacks observed on August 3, 2025.
  • Malicious traffic originated from multiple countries and targeted systems worldwide.
  • Attack patterns shifted after August 5 to also focus on FortiManager services.
  • Activity often predicts the discovery of security flaws in affected technologies within weeks.

Cybersecurity researchers have detected a significant increase in brute-force attempts against Fortinet SSL VPN systems. Threat intelligence firm GreyNoise observed this coordinated campaign on August 3, 2025, identifying participation from more than 780 unique IP addresses.

- Advertisement -

In the 24 hours before the report, 56 unique IP addresses engaged in these attacks. GreyNoise classified all of them as malicious. The origins of this traffic included the United States, Canada, Russia, and the Netherlands. Attackers aimed at targets located in the United States, Hong Kong, Brazil, Spain, and Japan.

According to GreyNoise, the attackers specifically targeted Fortinet SSL VPNs, not using random or opportunistic methods. “Critically, the observed traffic was also targeting our FortiOS profile, suggesting deliberate and precise targeting of Fortinet’s SSL VPNs,” the company said. Researchers detected two main waves: an ongoing long-term attack connected to a single network signature, and a more concentrated short-term burst with a separate signature.

After August 5, the firm saw a change in attack focus. “While the August 3 traffic has targeted the FortiOS profile, traffic fingerprinted with TCP and client signatures—a meta signature—from August 5 onward was not hitting FortiOS,” GreyNoise explained. Instead, this latter wave targeted FortiManager services. This shift signaled to researchers that attackers may be reusing the same tools or infrastructure to go after different Fortinet systems.

Further investigation found that similar attack fingerprints were first noticed in June, possibly indicating the initial use or testing of brute-force tools on a home network or via a residential proxy.

- Advertisement -

GreyNoise highlighted that spikes in attacks like these often come before the public disclosure of a new vulnerability in the targeted technology, usually within six weeks. These patterns commonly impact enterprise systems such as VPNs and firewalls, which are frequent targets for sophisticated threat groups.

The Hacker News has contacted Fortinet for comment and will provide updates if a response is received.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Senators Probe SEC Over Favoritism in Trump-Linked Crypto Cases

Two Democratic senators, Richard Blumenthal and Elizabeth Warren, are demanding answers from SEC Chair...

Sen. Blumenthal Probes SEC for Crypto Favoritism to Trump Allies

Connecticut Senator Richard Blumenthal has formally requested records from the Securities and Exchange Commission...

SpaceX may bar Robinhood, SoFi from IPO share sales – Reuters

SpaceX is reportedly considering excluding platforms like Robinhood (HOOD) and SoFi from its upcoming...

Nium Launches Stablecoin Card Platform via Visa, Mastercard

Nium has launched a platform enabling businesses to issue VISA and Mastercard cards funded...

BlackRock CEO Larry Fink’s 2026 Pay Hits $37.7 Million

BlackRock CEO Larry Fink's total compensation surged to $37.7 million for his role leading...

Must Read

Forex Trading Vs Crypto Trading: Which One Should You Choose?

So you're trying to decide between two types of trading: Forex and cryptocurrency.Forex trading is the big player in the trading world, with lots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading