Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


xpd

xpd

Geek of Coastguard
14223 posts

Uber Geek
+1 received by user: 4695

Retired Mod
ID Verified
Trusted
Lifetime subscriber

#324954 18-Jun-2026 16:11
Send private message quote this post

https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks/

 

"Researchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself."

 

Quite a few NZ companies affected. 

 

 





XPD / Gavin

 

LinkTree

 

 

 


Create new topic
geek3001
333 posts

Ultimate Geek
+1 received by user: 512

ID Verified
Subscriber

  #3504049 18-Jun-2026 16:36
Send private message quote this post

Am I reading this right, this breach has arisen because the device had a logon interface ultimately providing admin access, open to the public internet?

 

And, no one noticed / was monitoring for, a HUGE volume of logon attempts via said interface?




gjm

gjm
816 posts

Ultimate Geek
+1 received by user: 123


  #3504052 18-Jun-2026 16:46
Send private message quote this post

can check domains here if you're interested https://www.hudsonrock.com/fortinet and yes, a few big NZ names are listed





Do surveys for Beer money (referral link) - Octopus Group 

 

Link for buying beer (not affiliated, just like beer) - Good George


gzt

gzt
19139 posts

Uber Geek
+1 received by user: 8252

Lifetime subscriber

  #3504060 18-Jun-2026 17:03
Send private message quote this post

geek3001: Am I reading this right, this breach has arisen because the device had a logon interface ultimately providing admin access, open to the public internet?

I don't think you're reading that right.



gjm

gjm
816 posts

Ultimate Geek
+1 received by user: 123


  #3504067 18-Jun-2026 17:20
Send private message quote this post

The way I read it was that the management plane was exposed to the internet... how do you read it?





Do surveys for Beer money (referral link) - Octopus Group 

 

Link for buying beer (not affiliated, just like beer) - Good George


lxsw20
3736 posts

Uber Geek
+1 received by user: 2227

Subscriber

  #3504068 18-Jun-2026 17:40
Send private message quote this post

geek3001:

 

Am I reading this right, this breach has arisen because the device had a logon interface ultimately providing admin access, open to the public internet?

 

And, no one noticed / was monitoring for, a HUGE volume of logon attempts via said interface?

 

 


If you're lazy / a bad admin you can certainly configure a Fortigate that way, but i don't think thats the issue here.


PolicyGuy
1840 posts

Uber Geek
+1 received by user: 1796

ID Verified
Lifetime subscriber

  #3504070 18-Jun-2026 17:50
Send private message quote this post

gjm:

 

can check domains here if you're interested https://www.hudsonrock.com/fortinet and yes, a few big NZ names are listed

 

 

That site reports

 

  • 44 in *.co.nz
  • 4 in *.net.nz
  • 2 in *.org.nz
  • none in *.ac.nz, *.govt.nz, *.iwi.nz, *.mil.nz or .school.nz

 
 
 
 

Shop now for Lego sets and other gifts (affiliate link).
lxsw20
3736 posts

Uber Geek
+1 received by user: 2227

Subscriber

  #3504071 18-Jun-2026 17:53
Send private message quote this post

NZ schools have moved away from Fortigate. 


gokiwi64
44 posts

Geek
+1 received by user: 31


  #3504661 19-Jun-2026 16:05
Send private message quote this post

We use Fortigates as do several other Uni's , however in FortiOS 7.6 (sub version 3) and later SSL VPN is fully deprecated.


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.