「FortiBleed」災難:75,000 台防火牆如何成為駭客的敞開大門

FortiBleed vulnerability Fortinet firewall security enterprise network attacks Patching Paradox cybersecurity breach 2026
E
Elena Voss

Senior Cybersecurity Analyst & Privacy Advocate

 
2026年6月29日
4 分鐘閱讀
「FortiBleed」災難:75,000 台防火牆如何成為駭客的敞開大門

TL;DR

• FortiBleed 攻擊透過憑證竊取,導致全球 75,000 台 Fortinet 防火牆遭到入侵。 • 攻擊者鎖定暴露的管理介面以滲透企業網路。 • 「修補悖論」導致舊版 SHA-256 憑證在韌體更新後依然脆弱。 • 數據顯示針對大型財星 500 大企業的憑證嘗試次數高達數十億次。 • 資安專家呼籲立即重設密碼,以清除舊版雜湊漏洞。

「FortiBleed」災難:75,000 台防火牆如何成為駭客的敞開大門

這正是讓資安長(CISO)徹夜難眠的惡夢場景:一場名為「FortiBleed」的大規模自動化攻擊,已成功攻破全球 75,000 台 Fortinet 防火牆的防線。這並非單一的小型漏洞利用,此次事件已影響全球約半數面向網際網路的 Fortinet 基礎設施,使 194 個國家的網路門戶大開。

此次入侵的機制簡單得令人不寒而慄。攻擊者並非一定要尋找程式碼中的零時差漏洞(Zero-day),他們鎖定的是憑證。透過竊取管理設定檔,這些攻擊者得以手握通往企業網路的鑰匙,長驅直入。

Kudelski Security 的資安研究人員一直在追蹤這場災難,數據令人震驚。我們看到超過 73,000 個獨特的防火牆 URL 和超過 21,000 個網域成為目標。攻擊規模之大——針對 FortiGate 目標發動了 11.6 億次憑證嘗試,針對 MSSQL 伺服器發動了 21 億次嘗試——足以說明這場行動的規模。這不是外科手術式的精準打擊,而是一場地毯式的轟炸行動。

受害者名單宛如一份財星 500 大企業(Fortune 500)名單:三星(Samsung)、康卡斯特(Comcast)、鴻海(Foxconn)、西門子(Siemens)、聯想(Lenovo)、資誠(PwC)、埃森哲(Accenture)以及甲骨文(Oracle)。情況甚至更糟,據報導,一家土耳其的北約(NATO)國防承包商在基礎設施遭入侵後,機密文件遭到竊取。共同點是什麼?這些設備大多將 FortiGate 管理介面暴露在公共網際網路上。到了 2026 年,我們本應更謹慎,但現實卻是如此。

Critical FortiBleed Vulnerability Compromises Over 70,000 Fortinet Firewalls in Active Enterprise Network Attacks

圖片來源:SOCFortress

「修補悖論」(Patching Paradox)

為什麼會發生如此大規模的事件?這歸結於研究人員所稱的「修補悖論」。

Fortinet 最終將其憑證儲存升級為強大的 PBKDF2 雜湊演算法,這是好消息。壞消息是,該更新並未對現有的密碼進行回溯性重新雜湊(re-hash)。如果您更新了韌體,但沒有手動登入以觸發密碼重設,您的憑證仍會以舊版且脆弱的 SHA-256 格式儲存。

這是一個典型的「設定後就不管」而導致反噬的案例。管理員以為更新讓他們固若金湯,但舊版的雜湊值依然存在,等待被破解。

Hudson Rock 提供的數據顯示,這些設定檔被竊取是多麼容易。攻擊者很可能是一個精密的俄語系犯罪集團,他們不需要是天才,只需要一個高效能的 45-GPU 叢集就能破解這些舊版雜湊值。一旦取得憑證,標準密碼複雜度所提供的「安全性」就完全失效了。

損害報告

類別 詳細資訊
受影響設備總數 約 75,000 台
全球覆蓋範圍 194 個國家
主要攻擊途徑 暴露的管理介面
憑證漏洞 非回溯性的 PBKDF2 雜湊

現在該怎麼辦?

如果您正在使用 Fortinet 設備,請停止閱讀並立即檢查您的日誌。「FortiBleed」行動並未減緩,如果您的管理介面正對著公共網際網路,您基本上是在邀請駭客進門喝咖啡。

以下是您的緊急檢查清單:

  • 切斷公共存取: 如果您的 FortiGate 管理介面可以從公共網際網路存取,請立即拔掉連線。將其限制為僅限內部存取。
  • 強制重新雜湊: 不要以為韌體更新已經完成了所有工作。您需要對管理帳戶執行手動密碼重設,以強制轉換為 PBKDF2。
  • 搜尋異常跡象: 掃描您的日誌,尋找任何看起來異常的活動。檢查是否有未經授權的登入模式或不應存在的設定檔匯出。如果發現這些跡象,請假設您已經遭到入侵。
  • 驗證一切: 再次確認您的韌體是最新的,但不要止步於此。請確認密碼更新程序確實已經完成。

此次入侵的規模是一個嚴厲的提醒:安全性不僅僅是套用修補程式,還在於了解這些修補程式如何與您的舊有環境互動。隨著對 FortiBleed 的調查持續進行,焦點正從「這是怎麼發生的?」轉向「他們還拿走了什麼?」。

目前,請將您設備群中的每一台 Fortinet 設備都視為潛在的負債。認為防火牆就是堡壘的時代已經正式結束了。

E
Elena Voss

Senior Cybersecurity Analyst & Privacy Advocate

 

Elena Voss is a former penetration tester turned cybersecurity journalist with over 12 years of experience in the information security industry. After working with Fortune 500 companies to identify vulnerabilities in their networks, she transitioned to writing full-time to make complex security concepts accessible to everyday users. Elena holds a CISSP certification and a Master's degree in Information Assurance from Carnegie Mellon University. She is passionate about helping non-technical readers understand why digital privacy matters and how they can protect themselves online.

相關新聞

Outdated OpenVPN Implementations Expose Commercial VPN Clients to Critical Vulnerabilities and Security Risks
OpenVPN vulnerabilities

Outdated OpenVPN Implementations Expose Commercial VPN Clients to Critical Vulnerabilities and Security Risks

A 2026 security audit reveals many commercial VPNs use outdated, vulnerable OpenVPN versions. See which providers are leaving your data exposed to RCE attacks.

作者: James Okoro 2026年8月5日 4 分鐘閱讀
common.read_full_article
SonicWall VPN Vulnerabilities and AI-Powered Hacking Campaigns Pose New Risks to Enterprise Infrastructure
SonicWall VPN vulnerabilities

SonicWall VPN Vulnerabilities and AI-Powered Hacking Campaigns Pose New Risks to Enterprise Infrastructure

Hackers are exploiting SonicWall VPNs via CVE-2024-40766 and credential stuffing. Learn how to secure your enterprise infrastructure against these attacks.

作者: Viktor Sokolov 2026年8月4日 4 分鐘閱讀
common.read_full_article
Amazon Threat Intelligence Links North Korean Hackers to Malicious npm Supply Chain Attack
npm supply chain attack

Amazon Threat Intelligence Links North Korean Hackers to Malicious npm Supply Chain Attack

Amazon threat intelligence links North Korean hackers to malicious npm supply chain attacks. Discover how popular libraries like axios were weaponized.

作者: Elena Voss 2026年8月3日 4 分鐘閱讀
common.read_full_article
AWS Threat Intelligence Report Links North Korean Hackers to Open-Source Supply Chain Attacks
AWS threat intelligence

AWS Threat Intelligence Report Links North Korean Hackers to Open-Source Supply Chain Attacks

AWS threat report reveals North Korean hackers are poisoning open-source repositories to infiltrate cloud environments and harvest developer credentials.

作者: James Okoro 2026年8月2日 5 分鐘閱讀
common.read_full_article