The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were…
A ransomware operation linked to the FortiBleed campaign, with an operator using FortiBleed infrastructure to access negotiation panels and deploy ransomware.
A ransomware operation linked to the FortiBleed campaign, with an operator using FortiBleed infrastructure to access negotiation panels and deploy ransomware.
A large-scale credential-harvesting operation targeting FortiGate firewalls globally, stealing over 110 million credentials and linked to INC and Lynx ransomware operations.
Threat actors are actively exploiting three security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. The flaws include CVE-2026-39813…
Active DirectoryAI-generated exploitcommand injectioncredential harvesting
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to Fortinet customers following the discovery of a widespread…
Suspected Russian-speaking threat actors compromised over 30,000 Fortinet firewalls across 194 countries in a large-scale credential harvesting campaign dubbed FortiBleed. They used…
Hudson Rock provided a follow-up analysis of the FortiBleed campaign, reporting 73,932 unique firewall URLs targeted and 21,632 unique affected domains.
credential harvestingFortiBleedFortinetHudson Rock
The UK National Cyber Security Centre (NCSC) described FortiBleed as a global campaign targeting internet-facing Fortinet firewalls and VPN gateways using brute-force,…
The FortiBleed campaign is a global cyberattack targeting internet-accessible Fortinet FortiGate devices, compromising 86,644 devices as of June 19, 2026. The attack…