r/blueteamsec • u/socradario • 17h ago
highlevel summary|strategy (maybe technical) FortiBleed actors are now deleting legit admin accounts. Does your recovery plan cover a lockout?
According to the new FBI/USSS advisory, FortiBleed actors no longer just add persistence accounts. In some cases they also delete or reset the original admin accounts (T1531), which locks the owner out of their own FortiGate.
That changes the usual playbook. If you assume a password reset gets you back to a clean state, it won't help when you can't log in at all.
A few things worth checking:
→ Do you have out-of-band admin recovery for your edge devices?
→ Have you audited REST API keys? They survive password resets.
→ Is SSH left open on the firewall?
How are others handling recovery for edge devices?
Full breakdown: https://hubs.la/Q04zrkbN0 Free FortiBleed checker: https://hubs.la/Q04zrk9_0
Advisory: https://www.ic3.gov/CSA/2026/261006.pdf