INSIGHT DETAIL
Firewall & VPN Security
How Does a Firewall Turn into an Entry Point for Attackers? The FortiBleed ExampleOne of the most critical systems used to protect a company's network is the firewall.
.png)
One of the most critical systems used to protect a company's network is the firewall.
A firewall acts as a checkpoint between the corporate network and the internet, determining which connections are allowed in and which are blocked. Meanwhile, a VPN (Virtual Private Network) enables employees to connect to corporate systems while working remotely securely.
Normally, the function of these systems is to keep attackers out.
However, the FortiBleed incident highlighted a significant risk. If the access credentials for a security system are compromised, that very system can become a gateway for an attacker to enter the corporate network.
A report published by Reuters on June 17, 2026, announced that Fortinet was investigating a large-scale credential-harvesting campaign—an effort to collect login details such as usernames and passwords targeting its FortiGate firewall and VPN devices. You can access the Reuters report on FortiBleed here.
One of the attackers' targets was internet-facing FortiGate and VPN login interfaces.
One of the methods employed was a brute-force attack.
In its simplest form, a brute-force attack involves the automated testing of numerous username and password combinations until the correct password is found.
For instance, imagine an attacker has identified an account named "admin." Using automated tools, thousands of different passwords can be tested against this account within seconds. If the password is weak, or if a password used on another platform has been reused here, the likelihood of a successful login increases.
Similarly, attackers may attempt to use usernames and passwords compromised in previous data breaches; this technique is known as credential stuffing.
In a statement dated June 19, 2026, Fortinet explicitly clarified that FortiBleed was not a newly discovered Fortinet vulnerability. According to the company, attackers were reusing credentials obtained from previous incidents and employing brute-force methods against systems with weak password security and no Multi-Factor Authentication (MFA) enabled.
If an attacker can reach the network's entry point instead of directly targeting an employee's computer, they gain a significant strategic advantage.
For instance, once an authorised FortiGate account is compromised, an attacker can examine network configurations, alter security settings, or attempt to move deeper into the company's internal systems.
In cybersecurity, this process is known as "lateral movement." It means the attacker does not remain on the initially compromised system but attempts to reach other servers, accounts, or corporate systems from there.
The Cyber Security Agency of Singapore also warned that administrator or VPN accounts compromised via FortiBleed could be used to move laterally into internal corporate networks.
The situation later escalated in severity. Research published in July 2026 revealed links between certain access points compromised via FortiBleed and the INC and Lynx ransomware operations.
Simply installing a firewall is not enough.
Using a VPN does not automatically guarantee security.
Strong, unique passwords should be used, especially for administrator and VPN accounts. MFA should also be enabled, while internet-facing management panels should be restricted as much as possible.
The lesson from FortiBleed is quite simple:
A device installed for security purposes can become an entry point for attackers if not managed correctly. Therefore, security devices should be viewed not merely as a wall protecting the company, but as critical systems that themselves require constant protection.
Disclaimer
This content has been prepared solely for informational purposes and to raise cybersecurity awareness.