#1
The Hacker News
general
June 23, 2026 at 18:20 UTC
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
By [email protected] (The Hacker News)
AI Summary
The 'FortiBleed' campaign, attributed to a Russian-speaking initial access broker (IAB) active since at least February 2026, has targeted over 430,000 FortiGate firewalls globally using a custom Golang-based credential sniffer, harvesting more than 110 million credentials. The operation involves collecting credential lists, scanning for exposed services, brute-forcing accessible systems, and deploying bespoke tooling. Security teams managing FortiGate deployments should treat this as an active, ongoing threat requiring immediate credential rotation and access review.
Relevance score: 92.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →