2026.07.02
95%
This article directly updates the FortiBleed event by linking the credential-harvesting campaign to ransomware operations, reporting that SOC Radar found a shared operator tied to both INC Ransom and Lynx affiliate panels and linked at least 12 ransomware attacks to FortiBleed victims.
Ionut Arghire
2026.07.02
95%
This source updates the same FortiBleed campaign by adding evidence that harvested FortiGate credentials were used in follow-on ransomware attacks, specifically linking the operation to INC and Lynx, and adding scope figures on scanned portals, admin compromise, domain takeover, and ransomware deployment.
Lawrence Abrams
2026.07.01
98%
This article directly advances the same FortiBleed event by linking the campaign to INC and Lynx ransomware operators, expanding the known scope to 430,000 targeted FortiGate devices and about 19,000 with sniffers deployed, identifying more operational servers, and noting suspected use of an undisclosed Nextcloud zero-day plus persistent backdoor accounts named 'adminin'.
Arctic Wolf Labs
2026.06.24
95%
This is a direct follow-up on the same FortiBleed campaign and adds concrete reverse-engineering details about the recovered CyberStrike Harvester tool, the operator workflow, credential-stuffing and password-spraying tradecraft, offline cracking pipeline, post-authentication capture processing, and the assessment that the campaign is likely an initial-access and credential-monetization operation rather than one primarily driven by a Fortinet CVE exploit.
Ionut Arghire
2026.06.23
95%
This is a direct update on the same FortiBleed campaign, adding attribution to a likely Russian-speaking initial access broker, explaining that the operation is multi-vendor rather than Fortinet-only, detailing the custom FortigateSniffer tool and SSH brute-force intrusion method, and expanding the estimated scale to 110 million captured credentials and 430,000 FortiGate devices in scope.
Lawrence Abrams
2026.06.22
96%
This directly updates the same FortiBleed campaign by adding new findings that the actor used a custom Golang-based sniffer on compromised FortiGate devices to capture RADIUS, NTLM, Kerberos, LDAP, email, database, and other authentication material, reinforcing that the campaign is an ongoing initial-access operation rather than just a dump of old credentials.
Ionut Arghire
2026.06.22
98%
This is a direct update on the same FortiBleed campaign, adding Fortinet's response that the activity does not rely on a new vulnerability, ties it to reused credentials and brute-force attacks, cites prior FortiCloud SSO flaws CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719, and says over 86,000 working credentials were compiled across 194 countries.
info@thehackernews.com (The Hacker News)
2026.06.19
94%
This appears to be an update on the same FortiBleed campaign, adding CISA warning context and a much larger observed impact count of 86,644 exposed or affected FortiGate devices.
Ionut Arghire
2026.06.19
98%
This is a direct update on the same FortiBleed campaign, raising the count from more than 30,000 to 86,644 valid credentials, adding CISA hardening guidance, and citing additional validation from Hudson Rock, Huntress, Kevin Beaumont, and Bob Diachenko about scope, recency, and follow-on compromises.
Sergiu Gatlan
2026.06.19
97%
This article is a direct update on the same FortiBleed credential-leak campaign, adding CISA's warning and mitigation guidance, an updated scale of roughly 74,000 exposed credentials, and additional reporting that threat actors used the leaked credentials to target internet-accessible Fortinet devices across government and private-sector organizations.
Arctic Wolf Labs
2026.06.17
98%
This is the same underlying FortiBleed event and adds a defender-focused summary of the scope across 194 countries, the estimate of 30,791 to 75,000 affected devices, and Fortinet-specific mitigation details about legacy SHA-256 password hashes persisting after upgrades unless admins log in or reset passwords.
2026.06.17
98%
This is the same FortiBleed credential-theft campaign and updates the scope from more than 30,000 to around 75,000 compromised Fortinet devices, adds verification from Hudson Rock and Kevin Beaumont that the credentials are real, and adds details about 21,632 affected domains across 194 countries and at least four full compromises including a Turkish NATO defense contractor.
Lawrence Abrams
2026.06.17
96%
This article appears to be a direct update on the same FortiBleed event, adding that an exposed server contained credentials for 73,932 Fortinet/FortiGate VPN URLs, with usernames, email addresses, and plaintext passwords, along with claimed evidence of large-scale brute-force and compromise activity across 194 countries.
Eduard Kovacs
2026.06.17
100%
The article introduces a separate, concrete campaign dubbed FortiBleed involving large-scale compromise of Fortinet firewalls and VPN gateways, not just exploitation of the already tracked FortiSandbox CVE story.