🔥 この記事の詳細
2026-10-08 更新
B
今週中

FortinetのFortiGateおよびSSL VPNアプライアンスを標的とした「FortiBleed」キャンペーンが継続しており、攻撃者が管理者のパスワード…

脆弱性🌐 英語ソース📰 5記事🌐 3 countries
🇺🇸 US (3) · 🇹🇼 Taiwan · 🇬🇧 UK
🖥️ 製品Fortinet
📅 2026-10-08📰 securityweek
📌 一言でいうと
FortinetのFortiGateおよびSSL VPNアプライアンスを標的とした「FortiBleed」キャンペーンが継続しており、攻撃者が管理者のパスワードを変更して組織をデバイスから締め出す事例が報告されています。攻撃者は侵害済みの認証情報やブルートフォース攻撃を用いてデバイスを乗っ取っており、世界194カ国で約86,000台以上のデバイスが侵害されたと推定されています。FBIと米国秘密警察(USSS)が共同で注意喚起を行っています。
🔍該当判定
  • Fortinet社の『FortiGate』を導入して利用している
  • FortiGateの『SSL-VPN』機能を有効にして外部からアクセスさせている
  • FortiGateの管理画面に、単純なパスワードを設定している、または多要素認証(MFA)を導入していない
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. 管理者アカウントのパスワードを強力なものに変更し、多要素認証 (MFA) を強制的に適用すること。 2. 不審なログイン試行や設定変更がないか、監査ログを詳細に確認すること。 3. インターネットから直接アクセス可能な管理インターフェースを制限し、VPN経由などの安全な経路に限定すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Fortinet製品を標的とした「FortiBleed」攻撃への対応について

お疲れさまです。Fortinet製品を標的とした攻撃キャンペーンに関する情報共有です。

■ 概要
「FortiBleed」と呼ばれる攻撃キャンペーンにより、FortiGateおよびSSL VPNアプライアンスが侵害される事例が多発しています。攻撃者は侵害済みの認証情報やブルートフォースを用いて侵入し、管理パスワードを変更して正当な管理者を締め出す(Lock-out)挙動が確認されています。

■ 影響範囲
- 対象製品: Fortinet FortiGate firewalls, SSL VPN appliances
- 状況: インターネットに公開されており、認証保護が不十分なデバイス

■ 対応手順
1. 全管理者のパスワードを即座に更新し、複雑性の高いパスワードを設定してください。
2. 全管理アカウントに対して多要素認証 (MFA) を必須化してください。
3. 管理インターフェースへのアクセス制限(信頼できるIPアドレスのみに限定)を再確認してください。
4. 認証ログおよび設定変更ログを確認し、身に覚えのない操作がないか調査してください。

■ 参考情報
- FBI/USSS Joint Advisory

対応優先度: 高
対応期限: 直ちに実施
Subject: [Urgent] Response to 'FortiBleed' Attacks Targeting Fortinet Devices

Dear IT/Security Team,

We are sharing critical information regarding the 'FortiBleed' attack campaign targeting Fortinet infrastructure.

■ Overview
Attackers are targeting FortiGate firewalls and SSL VPN appliances using compromised credentials and brute-force attacks. A critical aspect of this campaign is that attackers are changing administrative passwords to lock legitimate organizations out of their own devices.

■ Scope
- Affected Products: Fortinet FortiGate firewalls, SSL VPN appliances
- Risk: Internet-accessible devices with weak or compromised authentication

■ Required Actions
1. Immediately rotate all administrative passwords to strong, unique values.
2. Enforce Multi-Factor Authentication (MFA) for all administrative access.
3. Restrict administrative interface access to trusted IP addresses only.
4. Review audit logs for unauthorized login attempts or unexpected configuration changes.

■ Reference
- FBI and US Secret Service (USSS) Joint Advisory

Priority: High
Deadline: Immediate