FortiBleed Can Lock Out Businesses, Plus 3 Stories
A firewall is supposed to be the locked front door to a business network. Fortinet firewall security is no longer just a question of whether the current software is patched. The FortiBleed campaign has turned some Fortinet firewalls into something worse: a door the intruder can keep using while the owner discovers that the locks have been changed.
FortiBleed is a credential problem, not just a patch problem
The FBI and Secret Service issued a joint advisory on October 6 about an active global campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. SOCRadar verified more than 86,000 compromised devices across 194 countries. That number is large, but the mechanism matters more than the headline.
Attackers collected credentials and password hashes from prior leaks, infostealer logs, password spraying, and exposed FortiGate systems. They then used graphics processors to crack weaker legacy SHA-256 password hashes at scale. Once a credential worked, they could create new administrator accounts, explore the internal network, and package that access for sale to ransomware affiliates. Some victims have reportedly found their original administrator accounts disabled or altered.
Imagine a small manufacturer that lets an outside IT provider administer its firewall remotely. That public management page is convenient, right up until an attacker signs in with a credential stolen months earlier. The attacker adds an account with an ordinary-looking name, downloads the configuration, and tests whether the same password works elsewhere. The business can patch the current software and still leave that new account in place. That example is hypothetical, but every step follows the attack path the agencies documented.
So, what does a Fortinet customer actually do? First, stop exposing the management interface to the public internet. The agencies rank trusted-host restrictions as good, a local-in policy as better, and removing internet administration altogether as best. Then terminate active administrator and VPN sessions, reset those credentials, require phishing-resistant multifactor authentication, inspect the configuration for unfamiliar accounts and API keys, and compare it with a known-good copy. FortiOS 7.2.11 and later can use PBKDF2 for administrator-password storage, which deliberately makes offline cracking more expensive.
Notice what isn’t on that list: change one password, declare victory, and go home. If an attacker created a second account or moved into Active Directory, the original password was only the first problem. I’d treat any confirmed unauthorized login as an incident, preserve the logs, scope what changed, and only then evict the intruder. A clean configuration backup stored somewhere the firewall can’t rewrite is particularly valuable here. Who can erase the recovery copy matters just as much as whether a copy exists. That’s the same recovery question behind yesterday’s Veeam story: can the attacker reach the thing meant to save you?
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
A court blocks the federal voter-data consolidation plan
A federal judge ruled Friday that the Justice Department’s policy of collecting complete state voter rolls and comparing them with the federal SAVE immigration database was unlawful. The court’s decision vacated the policy, which the DOJ had used to flag people it considered potentially ineligible and ask states to remove them.
This isn’t just an election-law story with a database somewhere in the background. According to Reuters, the DOJ sought unredacted records that could include Social Security numbers and birth dates. The judge also found that the expanded SAVE data could be stale, particularly for immigrants who later became naturalized citizens. In other words, the matching system could turn old information into a current decision about a person’s right to vote.
That’s the technical lesson: combining two databases doesn’t magically improve either one. It can make an error more consequential because the match now looks official in two places. The DOJ says it is reviewing the decision, and separate litigation continues, so this may not be the final word. Voters don’t need to panic or send sensitive information to anyone who contacts them. Checking registration through an official state election website is reasonable, especially before the November 3 midterms.
The ruling also doesn’t mean every voter record disappears from every federal system. It addresses this particular DOJ policy, the way the data was collected and compared, and the authority used to demand changes from states. That boundary matters. A court can stop one data pipeline without resolving every argument about voter-list maintenance, and the government can appeal.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Cleo AI refunds are coming, and so will the scams
The Federal Trade Commission says it will return more than $15.8 million to 2,124,796 customers of the Cleo AI cash-advance app. The agency alleged that Cleo advertised access to hundreds of dollars when almost nobody received amounts close to that, charged extra for fast advances that sometimes arrived late, and made subscriptions difficult to cancel.
Eligible customers should receive an email by October 26, with PayPal payments beginning October 27. The practical warning is simple: the FTC says it won’t require a fee or bank-account information to issue a refund. A real payment program involving millions of people is also a ready-made story for scammers. Don’t use a phone number or link from an unexpected text; start from the FTC’s own notice.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
AI can help write a filing, but it can’t own the result
A federal judge in Arizona dismissed a 67-page employment complaint that she said appeared to have been generated by AI. The October 7 order described allegations that were repetitive, difficult to follow, and poorly connected to identifiable legal claims. The plaintiff may file an amended complaint, but she must draft its allegations herself. Future AI use in the case has to be disclosed and its output verified.
The useful distinction is that the court didn’t announce a universal ban on AI-assisted legal work. It objected to a document that failed the ordinary test for a complaint: tell the court what happened, which claims follow from those facts, and what relief is being requested. Whether the first draft came from a person, a template, or a model doesn’t transfer responsibility away from the signer. That applies outside court too. If an AI-generated contract, policy, tax letter, or customer notice carries your name, every sentence is still yours to defend.
AI can still be useful for outlining or finding questions you forgot to ask. It is a terrible substitute for deciding which facts are true, which authority actually applies, and what you’re willing to put your name under. The model doesn’t face the judge, the customer, or the regulator. You do.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources and further reading
- FBI and U.S. Secret Service: FortiBleed Operations Continue Targeting Exposed Systems
- The Record: FBI and Secret Service add to FortiBleed warning
- U.S. District Court: Common Cause v. Department of Justice decision
- Reuters: Judge rules DOJ voter-roll policy unlawful
- Federal Trade Commission: Cleo AI refund notice
- U.S. District Court for the District of Arizona: AI-drafted complaint order
- Reuters: Judge dismisses complaint citing AI hallmarks
Photo by Field Engineer on Pexels.
