ACSC flags active threat hitting Australian firewalls and VPNs
ACSC flags active threat hitting Australian firewalls and VPNs. Australia’s Cyber Security Centre (ACSC) has issued an urgent alert over a campaign dubbed FortiBleed that targets Fortinet firewalls and VPN gateways. The Australian government agency warned that the activity uses exposed credentials and brute-force techniques to gain remote access, alter security controls, and change settings on affected devices and the networks behind them. The alert, issued June 22, 2026, says FortiBleed is not a zero-day: there is no patch to close the exposure. Fortinet published its own analysis three days earlier, attributing the activity to threat actors recycling credentials from two earlier incidents and focusing on systems with weak passwords and no multi-factor authentication (MFA). The report also links the pattern to ransomware deployment, triggering notification requirements under Australia’s Cyber Security Act 2024, including a 72-hour reporting window to the ASD for ransomware or cyber extortion payments.






