top of page

This week's cyber threat: NCSC warns of targeting against Fortinet firewalls and VPN gateways

  • Jun 24
  • 1 min read


This week's top threat: NCSC warns of targeting against Fortinet firewalls and VPN gateways

This is a public summary from the Black Cat Weekly Threat Briefing for 2026-W25.

The NCSC says Fortinet firewalls and VPN gateways have been targeted globally, with indications of potential UK impact. A threat actor leaked a credential database following attempts against internet-facing FortiGate and VPN portals.

Why it matters for small businesses

These devices matter because they are designed to connect external users to internal systems. A compromised firewall or VPN account can give an attacker a route around controls that only monitor laptops and servers. Reused passwords increase the risk, and persistence on an edge device can mean that changing credentials alone is insufficient.

What to do this week

  • Confirm whether your organisation or IT provider operates Fortinet devices with SSL VPN enabled.

  • Check the NCSC-linked FortiBleed checker and investigate unauthorised accounts or unexpected log activity.

  • If compromise is suspected, isolate the device from both the internet and internal network and preserve logs before resetting it.

  • Update supported systems, remove unsupported devices and ensure management interfaces are not internet-facing.

  • Replace default, shared or reused administrator passwords and require MFA for VPN and device-management access.

Read the full weekly briefing

Black Cat members receive the full Weekly Threat Briefing, including ransomware activity, exploited vulnerabilities, recommended actions and further reading.

 
 
 

Comments


bottom of page