Visualização normal

Antes de ontemStream principal
  • ✇Security Affairs
  • Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents Pierluigi Paganini
    Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and what defenders should do in response. From a broader perspective, cybercriminals and fore
     

Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents

30 de Julho de 2026, 14:16

Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders.

Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and what defenders should do in response. From a broader perspective, cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders.

Beyond frontier models like Mythos, the report details how modern offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, Ethiack Nebula, and specialized LLMs like CyberStrike-OffSec-35B, have lowered the barriers to vulnerability identification and exploitation. Increasingly, these tools are becoming available to financially motivated cybercriminals, who would otherwise lack the technical abilities to carry out sophisticated attacks.

Artificial intelligence is rapidly transforming offensive security from isolated automation into autonomous, multi-agent systems capable of mapping attack surfaces, identifying vulnerabilities, validating exploits, and producing technical reports with minimal human intervention. According to Resecurity, AI agents are redefining how cybersecurity assessments are performed while also introducing new dual-use risks – leading to data breaches and network intrusions orchestrated via AI.

“Unlike traditional security automation, which executes predefined scripts, AI offensive agents operate as autonomous decision-making systems. They combine large language models, persistent memory, and specialized security tools to continuously plan, execute, evaluate, and adapt their actions throughout an assessment.” reads the report. “Rather than following a fixed sequence of commands, they dynamically adjust their strategy based on the results of previous actions, allowing them to perform complex, multi-stage security assessments with minimal human intervention.”

Resecurity examined the capabilities, architectures, and misuse of of modern AI offensive security tooling, highlighting how autonomous agents are reshaping both legitimate penetration testing and real-world cyber threats. Through case studies including FortiBleed, JadePuffer, and GTG-2002, it demonstrates that AI-assisted cyber operations are no longer theoretical.

While AI dramatically improves the speed, scale, and efficiency of offensive security, human expertise remains essential for creative exploitation, business logic analysis, and strategic decision-making. As autonomous AI continues to evolve, organizations should adopt a hybrid security model that combines AI-powered assessment with human oversight, continuous exposure validation, and strong defensive controls to prepare for increasingly automated cyber threats.

Resecurity forecasts cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders.

“AI-powered offensive security tools represent a genuine leap forward for defensive security. They can find and validate bugs faster, make pentesting more affordable, and help overworked security teams scale their work.” concludes the report. “But they are inherently dual-use. The same autonomous reconnaissance, exploitation, and post-exploitation engines designed for authorized testing can be pointed at real infrastructure by criminals, ransomware groups, and state actors with minimal modification.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, AI offensive)

  • ✇ASEC BLOG
  • June 2026 Dark Web Breach Incident Trend Report ATCP
    Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]
     

June 2026 Dark Web Breach Incident Trend Report

Por:ATCP
8 de Julho de 2026, 12:00
Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]

FortiBleed Credential Theft Connected to INC and Lynx Ransomware

FortiBleed, the Fortinet credential theft campaign, is now connected to INC Ransom and Lynx, with a Nextcloud zero-day vulnerability also under investigation.
  • ✇Security Affairs
  • 430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link Pierluigi Paganini
    FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator with access to FortiBleed’s own infrastructure was found actively logged into the negot
     

430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link

2 de Julho de 2026, 07:37

FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks.

SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator with access to FortiBleed’s own infrastructure was found actively logged into the negotiation panels of both ransomware groups, handling ransom demands in real time.

FortiBleed has been documented since SOCRadar’s first report. The operation uses a custom tool written in Go called FortigateSniffer, which passively intercepts authentication traffic by abusing FortiOS’s own built-in packet diagnostic command across two dozen protocols.

The attacker never sends malicious payloads to the firewall. They just listen to the traffic the device generates itself. It’s a quiet way to collect credentials at scale, and it’s been running across more than 150 countries.

After the initial disclosure, SOCRadar continued mapping the campaign using Shodan, Censys, Validin, and its own scanning. That work turned up roughly 200 additional operational servers beyond the original dataset, a mix of credential sniffers and network scanners that hadn’t appeared in the first investigation. As the SOCRadar report states:

“Across the expanded infrastructure, STRU tracked scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets.” reads the report published by SocRadar. “On 354 of those, the actor completed the full attack chain: VPN compromise, access to the domain controller, and domain admin. STRU has confirmed at least 12 ransomware deployments stemming from this access, with hundreds of endpoints encrypted across affected organizations.”

That’s not credential theft sitting in a database waiting to be sold. That’s domain-level control of hundreds of organizations, obtained quietly through their own firewall. SOCRadar has confirmed at least 12 ransomware deployments traced directly to FortiBleed-derived access, with hundreds of endpoints encrypted across the affected organizations.

One of the newly discovered servers gave SOCRadar visibility into the group’s own internal environment. An operational security lapse in how the group managed its infrastructure exposed internal files, logs, and operational documentation. That’s what made the ransomware connection possible to prove rather than just infer.

Inside that environment, SOCRadar found an operator logged into negotiation panels for both INC Ransom and Lynx simultaneously.

INC Ransom has been active since mid-2023 and remains one of the more active ransomware-as-a-service operations by victim count. The INC RANSOM has claimed responsibility for the breach of at tens of organizations to date, including US hospice pharmacy  Xerox CorpOnePoint Patient Care, and Scotland’s National Health Service (NHS) Lynx appeared roughly a year later and is widely assessed as a direct evolution of INC. One operator, two brands, infrastructure traceable back to the credential harvesting campaign. The attribution case is direct.

SOCRadar also found a separately discovered open directory linked to INC Ransom and compared its contents against FortiBleed’s own target records. The victims matched.

“Comparing target and victim data from FortiBleed’s own infrastructure against a separately discovered INC-linked open directory, STRU found matching victims across both datasets, independent confirmation that the same organizations were being tracked by both the credential-harvesting operation and the ransomware group.” states SocRadar.

SOCRadar recovered an internal tracking document the group uses to manage its FortiGate targets, recording which credentials were used, which networks were accessed, and whether ransomware was eventually deployed. Analysis of this document points to a structured operation of roughly 20 people. A small core of primary operators handles the high-impact intrusions. Behind them sit dedicated specialists, and below those, a back-office layer of junior operators and technical support staff. It runs like a small company, with a division of labor that would look familiar on any org chart. (Except the product is ransomware.)

SOCRadar is withholding specific operator aliases, tooling details, and the full indicator set until the complete technical whitepaper publishes. That report will also cover a separate line of investigation into the group’s use of AI tools for vulnerability research, including work toward at least one undisclosed zero-day that SOCRadar is coordinating with the affected vendor through responsible disclosure.

The practical implication is direct.

This campaign isn’t an access broker quietly monetizing stolen credentials through underground markets at arm’s length from the actual attacks. The same infrastructure that collected the credentials is directly connected, through a shared operator, to the groups deploying ransomware on victim networks.

“The same access broker infrastructure that quietly intercepted authentication traffic across hundreds of thousands of firewalls is connected, through a shared operator, to two of the more active ransomware brands operating today.” concludes the report. “For organizations running FortiGate infrastructure, this raises the stakes on an already urgent finding: exposure to FortiBleed is not just a credential exposure risk, it is a potential precursor to ransomware.”

If your organization runs FortiGate infrastructure, the question isn’t whether your credentials were targeted. With 430,000 firewalls in scope and active scanning across 150 countries, the better question is whether your environment showed up in the 409 where admin access was confirmed, or the 354 where full domain compromise was achieved.

SOCRadar says the full indicator set will be in the forthcoming whitepaper. Watch for it.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇Security Affairs
  • FortiBleed: The Broker Who Turned 73,000 Firewalls Into a Product Catalog Pierluigi Paganini
    FortiBleed exposed valid credentials for 73,000+ Fortinet firewalls, revealing a large-scale access-brokering operation targeting organizations worldwide. In mid-June 2026, researcher Volodymyr “Bob” Diachenko found a live, exposed server containing working login credentials for tens of thousands of Fortinet firewalls, a data leak code-named FortiBleed. The headline number, valid remote-access logins for 73,932 devices across 21,632 organizations in 194 countries, roughly half of every inter
     

FortiBleed: The Broker Who Turned 73,000 Firewalls Into a Product Catalog

24 de Junho de 2026, 06:35

FortiBleed exposed valid credentials for 73,000+ Fortinet firewalls, revealing a large-scale access-brokering operation targeting organizations worldwide.

In mid-June 2026, researcher Volodymyr “Bob” Diachenko found a live, exposed server containing working login credentials for tens of thousands of Fortinet firewalls, a data leak code-named FortiBleed. The headline number, valid remote-access logins for 73,932 devices across 21,632 organizations in 194 countries, roughly half of every internet-facing FortiGate on the planet, is what made it news. The server was left open by accident, complete with the tools, logs, scripts, and credential catalog of a running operation.

But a list of stolen passwords is the output of a crime, not the crime itself. Mysterium VPN traced the operation back to a single vendor trading under the handle “SantaAd” on an underground Russian-speaking cybercrime forum.

FortiBleed

The account has been building a vendor reputation since early 2025, and its post history reads like a product catalog with one obsession: Fortinet. Over recent months, the same seller auctioned remote-access credentials to named US manufacturers, listed thousands of Fortinet admin panels, and ran a standing advertisement buying fresh corporate access from US companies above a set revenue threshold.

“The single most telling piece of evidence in the whole affair isn’t a password; it’s the spreadsheet.” reads the report published by MysteriumVPN “The leaked data is annotated, organization by organization, with company name, sector, annual revenue, and employee count, and sorted into tiers by how much they’re worth.”

Espionage actors sort targets by intelligence value. This actor sorted them by price. The revenue column is what marks this as a financially motivated operation whose end product is resale — most likely to ransomware crews for whom a pre-validated foothold in a high-revenue company is exactly what they’re buying.

The operation ran on mostly off-the-shelf parts. A dedicated brute-force server generated and tested credential combinations at scale — over a billion device-and-password pairs drawn from a few thousand common starting points, running tens of thousands of simultaneous attempts through rotating proxy addresses. A separate cracking server ran an open-source password-cracking tool fed by a cluster of roughly 45 high-end GPUs rented by the hour. A third workstation handled manual work: writing code, managing seven disposable Kali Linux virtual machines, and navigating victim networks once access was established.

“The custom code carries the fingerprints of machine-generated software — emoji status messages, tidy ‘Step 1 / Step 2 / Step 3’ formatting, verbose explanatory comments, and ties back to an AI code-editor session created days before the campaign began.” continues the report.

The crew also deployed an AI-driven penetration-testing framework: a tool that lets an operator describe an objective in plain language and have software carry out the network attack automatically. Actions that once required a skilled, experienced attacker are now available to anyone who can rent a server and formulate a prompt.

The broker’s own candor is instructive. In one auction thread, when asked where the data came from, the seller said it was “mostly brute” and that the brute-forcing tool was written in-house. When asked how many credentials actually worked, they admitted that only a fraction had been confirmed valid and that the validation tool had broken. At one point an entire auction was pulled because “the dump had errors.” This is what access brokering looks like from the inside: a noisy, imperfect assembly line, not a clean heist.

“When this made the news, the broker didn’t go quiet. They updated a live auction for access to several thousand Fortinet devices, raised the starting price, and cited the news coverage as an authenticity guarantee.” A journalist’s writeup used as a sales testimonial. That’s a first.

The practical takeaway is architectural. The device organizations buy to keep strangers out became the front door a criminal crew walked through and then cataloged. Get the management interface off the public internet, enforce multi-factor authentication on VPN and admin access, some of the cracked credentials in this dataset were long and complex, which proves password strength alone doesn’t save you, and rotate every credential stored in the device configuration. Then assume your organization is already on a shopping list, because if it could appear in this dataset, access to your network may already be for sale.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FortiBleed)

FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation

22 de Junho de 2026, 07:25

FortiBleed targeted 430,000+ FortiGate devices, harvesting 110M credentials and enabling breaches through large-scale credential theft.

A new threat intelligence report from SOCRadar’s Threat Research Unit (STRU), the team that first identified and named the FortiBleed campaign, goes deeper than anything published so far on what is shaping up to be one of the most significant credential-theft operations of 2026.

The full report, titled Dismantling FortiBleed, is available here.

What is FortiBleed?

FortiBleed is a large-scale, financially motivated campaign targeting FortiGate firewalls globally. STRU first reported and named the campaign here. The numbers alone are staggering: over 430,000 FortiGate firewalls targeted, more than 110 million credentials identified across 659+ harvesting pipelines, and a confirmed breach of a NATO-aligned defense contractor.

What makes this report different

Most coverage of FortiBleed stops at the headline figures. This report doesn’t.

Starting from a single exposed directory flagged by security researcher Volodymyr “Bob” Diachenko, STRU traced the operation to more than 150 additional servers, building a near-complete picture of the actor’s infrastructure, tooling, and operational workflow. At the time of writing, the campaign is still actively sniffing over 19,000 devices, part of a broader pool of 80,553 identified targets.

That level of visibility is what separates this analysis from others.

A five-phase attack chain, fully reconstructed

The report walks through every stage of the operation in technical detail:

The actor starts with credential sourcing and mass reconnaissance, using Masscan for port sweeps, a custom Shodan_Recon tool for passive enrichment, and a purpose-built FortiProbe-fast binary to filter confirmed FortiGate devices from millions of raw scan results. Targets are then ranked by revenue before any exploitation resources are allocated, a step that reflects deliberate operational planning rather than opportunistic spraying.

Initial access comes through SSH brute-force using 16 wordlists specifically curated for FortiGate admin account naming conventions, alongside credential stuffing against SSL-VPN portals.

The core of the operation is a Golang-based tool called FortigateSniffer, which abuses the legitimate FortiOS diagnostic command diagnose sniffer packet to passively capture authentication traffic across 24 protocols from every compromised device, Kerberos, RADIUS, NTLM, RDP, LDAP, MSSQL, and more, without deploying any malware. The sniffer only runs between 07:00 and 18:00 Moscow Time, a deliberate evasion choice to blend in with normal business-hours traffic.

Captured hashes are cracked through a distributed GPU cluster managed via Hashtopolis, with Hashcat as the underlying engine and a Telegram bot providing live telemetry to a single hardcoded administrator. The actors also rented GPU capacity through vast.ai for additional cracking power.

The final phases cover lateral movement across Active Directory environments and, in at least one confirmed case, the targeted exfiltration of DFS backup data from a NATO-aligned defense contractor, triggered within minutes of Kerberos hashes being cracked offline.

Infrastructure and attribution

The actors operate from a network of loosely regulated Eastern European micro-hosters, with the core infrastructure segmented across four subnet blocks serving distinct roles: C2 aggregation, credential validation, sniffer deployment, and proxy rotation. The pentest lab environment itself runs seven Kali Linux virtual machines under QEMU/KVM, hardened with strict IPTables rules and designed for multi-operator remote access through shared tmux sessions.

Tooling comments in the Cyrillic alphabet suggest Russian origin. The actor profile is consistent with an Initial Access Broker selling access to ransomware groups, though the targeting of a NATO-aligned defense contractor raises the possibility of at least opportunistic collaboration with state-adjacent actors.

Who is being hit

The victim profile skews heavily toward SMBs: roughly 66% of affected organizations have fewer than 200 employees, and nearly 90% have annual revenues below $100 million. India, the United States, and Taiwan account for nearly a third of affected domains. IT services is the most targeted sector, a strategic choice, since compromising a managed service provider creates downstream access paths into customer environments.

The campaign is global and appears opportunistic rather than geopolitically focused, with meaningful victim counts across Latin America, the Middle East, and Europe as well.

What to do now

STRU recommends that organizations potentially in scope immediately rotate all credentials tied to Fortinet VPN and administrative interfaces, enforce MFA, remove FortiGate management interfaces from direct internet exposure, and review authentication logs for anomalous activity. SOCRadar has also released a free FortiBleed exposure checker at socradar.io/free-tools/fortibleed.

The campaign remains active. The full technical report, including the complete MITRE ATT&CK mapping, IoC lists, and infrastructure breakdown, is at socradar.io.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FortiBleed)

  • ✇Security Affairs
  • FortiBleed Exposes Global Credential-Spraying Operation Pierluigi Paganini
    FortiBleed exposed a massive campaign that made billions of login attempts against Fortinet VPNs, compromising organizations worldwide. FortiBleed wasn’t a targeted hack. It was a factory. A multi-operator crew ran an industrial-scale attack against Fortinet FortiGate SSL VPN devices worldwide, and security researcher Volodymyr “Bob” Diachenko of SecurityDiscovery.com caught them only because they left their own infrastructure exposed on the open internet in June 2026. “The crew mass-scan
     

FortiBleed Exposes Global Credential-Spraying Operation

20 de Junho de 2026, 05:37

FortiBleed exposed a massive campaign that made billions of login attempts against Fortinet VPNs, compromising organizations worldwide.

FortiBleed wasn’t a targeted hack. It was a factory. A multi-operator crew ran an industrial-scale attack against Fortinet FortiGate SSL VPN devices worldwide, and security researcher Volodymyr “Bob” Diachenko of SecurityDiscovery.com caught them only because they left their own infrastructure exposed on the open internet in June 2026.

“The crew mass-scans 320,777 FortiGate /remote/login endpoints and more than 247,000 Sophos /userportal endpoints. FortiGate logins are then sprayed with 3,639 base credential pairs across every target, 1.16 billion combinations in total, through a custom tool called forticheck running 25,000 threads.” reads the report published by Ransomnews.

A parallel campaign hit 163,650 MSSQL servers with 2.1 billion attempts at 50,000 threads. That’s not espionage; that’s automation.

Once they got in somewhere useful, they dropped network sniffers to pull cleartext credentials from HTTP, FTP, SMTP, LDAP, and other protocols.

“Once inside reachable infrastructure, the operators drop network sniffers that scrape cleartext credentials out of HTTP, FTP, SMTP, POP3, IMAP, LDAP, SNMP, and Telnet traffic.” states the report. “Intercepted Kerberos and NTLM hashes are shipped to a 45-way NVIDIA RTX 4090 cracking cluster orchestrated through Hashtopolis.”

With cracked credentials in hand, they replayed captured session cookies through OpenConnect to hijack live VPN sessions, then walked straight into Active Directory. Standard looting from there: AD dumps, fileshare exfiltration, Kerberos tickets, Group Policy templates.

The operators aren’t random. They work from Kali Linux virtual machines behind NAT so their command server never touches a victim’s Active Directory directly. Targets are ranked by revenue, with a top tier above 113 billion dollars, using open-source intelligence. Multiple operators work the same machines at once, coordinating over shared terminal sessions. The hash-cracking server, tellingly, was left running on default credentials. The same mistake they exploit in victims.

At least four organisations were fully compromised, across Japan, Taiwan, Vietnam, Iraq, and Turkey. The most serious claim involves a Turkish defence contractor with NATO ties whose classified defence documents were exfiltrated. Ransomnews hasn’t independently verified those contents and treats the attribution as the investigator’s assessment, not confirmed fact.

The working dataset covers 73,932 exposed FortiGate devices across 21,613 organisations in 207 countries. India leads on raw volume, and Latin American telecoms carry the densest device fleets. IT services, telecoms, financial services, and government are the most exposed sectors.

“In a random sample of exposed organisations, 88% also appeared in stealer-log or breach data and 38% had staff with active infostealer infections. Around 590 are already named on ransomware leak sites.” concludes the report.”An exposed FortiGate is rarely an isolated problem. It is one visible symptom of an organisation attackers have already found more than once.”

An exposed FortiGate isn’t a standalone problem. It’s a sign that attackers have already found the organisation more than once.

If you run FortiGate, take the management interface and SSL VPN off the public internet wherever possible. Rotate every administrator and local credential, upgrade FortiOS, and invalidate active VPN sessions so replayed cookies stop working. Reset exposed employee credentials too, not just the firewall accounts, because the infostealer overlap is too high to ignore.

The researchers also released a FortiBleed Checker to allow admins to check their domains.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FortiBleed)

  • ✇Security Affairs
  • CISA Warns of Active Exploitation Following FortiBleed Leak Pierluigi Paganini
    FortiBleed exposed credentials for 74,000 Fortinet devices, with attackers actively exploiting the leak to target systems worldwide. On June 18, CISA issued an emergency alert after reports surfaced that credentials for approximately 74,000 Fortinet firewalls and VPN gateways had been leaked in what researchers are calling FortiBleed. The agency confirmed that threat actors were actively using those credentials to target internet-accessible Fortinet devices across government and private-sect
     

CISA Warns of Active Exploitation Following FortiBleed Leak

20 de Junho de 2026, 05:10

FortiBleed exposed credentials for 74,000 Fortinet devices, with attackers actively exploiting the leak to target systems worldwide.

On June 18, CISA issued an emergency alert after reports surfaced that credentials for approximately 74,000 Fortinet firewalls and VPN gateways had been leaked in what researchers are calling FortiBleed. The agency confirmed that threat actors were actively using those credentials to target internet-accessible Fortinet devices across government and private-sector organizations worldwide.

“CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials.” reads the alert published by CISA. “This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways.”

This week, the security researcher Bob Diachenko found a server sitting open on the internet containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for tens of thousands of organizations. He posted about it on LinkedIn. Kevin Beaumont, one of the most trusted independent voices in network security, then obtained the dataset, worked through it with Hudson Rock, and confirmed what nobody wanted to hear.

“Massive Fortinet/FortiGate bruteforce/active exploitation campaign uncovered in action. Thousands of top vendors instances are listed in the files like this (see screenshot). This one alone has 21,634 domain names – from Chevron to Fortinet itself. All – with potentially working passwords to the FortiGate appliances obtained through various menas.” Bob Diachenko wrote on LinkedIn.
“Crooks use sophisticated hashcracking approach to get then plaintext passwords from the Fortigate configs and use them consequently in the internal network movement and takeover.”

The popular cybersecurity expert Kevin Beaumont confirmed that the data is legit and is related to around 75k devices.

“The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data.” reads the analysis published by Beaumont. “The data appears to have come from exports of config from the devices, as it includes things which are only visible from the device itself.”

Beaumont verified credentials at multiple organizations in the dataset personally and found them working. The IP addresses in this collection are largely different from the 2025 Belsen Group leak, which covered 15,000 devices. That earlier dump was old data from a 2022 zero-day. This one isn’t.

Based on Shodan polling, the FortiBleed dataset covers roughly 50% of all Fortinet firewall devices currently facing the internet.

“In a majority of cases, the Fortigate Management Interface is exposed to the internet on impacted devices.” states the expert.

According to Hudson Rock’s analysis, the 73,932 unique firewall URLs span 194 countries and 21,632 unique domains. Names appearing in the dataset according to Hudson Rock include Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and numerous government agencies and critical infrastructure operators. One entry in Diachenko’s screenshots alone listed 21,634 domain names, including Chevron and Fortinet itself.

Diachenko’s investigation went further after he found the attackers had accidentally left an open directory containing their own tooling, scripts, connection strings, logs, and analytics. What he found inside suggests a Russian-speaking multi-operator threat group conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets, plus 2.1 billion attempts against 163,650 Microsoft SQL Server systems.

The group reportedly intercepted SSL VPN authentication hashes and cracked them using a 45-GPU cluster managed through Hashtopolis. Multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey were described as fully compromised, including a Turkish NATO defense contractor from which classified documents were allegedly stolen.

The data appears to have come from exported device configurations rather than a simple credential scrape. That’s a meaningful distinction: config exports contain information you can’t get just by intercepting login traffic, which points toward actual device access at some point. How that access was obtained remains unknown: it may be one of the many documented Fortinet CVEs, or it may be something new.

One detail in the dataset that stands out is the business intelligence layer. Each entry includes the company’s industry, revenue, employee count, and country, formatted in a way Beaumont describes as very common in criminal markets for selling initial access. This wasn’t assembled for personal use. It was assembled for sale or coordinated deployment across a team. The attached comments on each target are essentially a sales catalog.

That means an attacker with these credentials can log in remotely, gain access to the firewall and therefore the network behind it, change security settings, and create backdoor admin accounts. Beaumont also noted that Fortinet moved to PBKDF2 credential storage in early 2025 firmware updates, but only for devices where admins had actually logged in after applying the update. Many devices were still storing passwords as SHA-256 with salt, which is crackable via brute force from a stolen config file.

Hudson Rock has published a free lookup tool at hudsonrock.com/fortinet where organizations can check if their domain appears in the dataset.

” It is unclear where Hunt Intelligence obtained the data from and how long it has been in circulation, however it is formatted in a way which looks like an eCrime gang — e.g. it lists the type of company, their revenue and country.” concludes Beaumont. “This is a very common format in eCrime circles when selling initial access information.”

CISA’s instructions are direct and non-negotiable for any organization running Fortinet equipment. Terminate all active SSL VPN and administrative sessions immediately. Reset every VPN and administrative password. Enable phishing-resistant multi-factor authentication on all admin interfaces. Review logs for unauthorized access or lateral movement.

Upgrade to the latest FortiOS release and have every admin log back in to trigger the re-hashing of stored credentials to PBKDF2. Remove the FortiOS management interface from public internet access unless absolutely necessary, and delete any unauthorized accounts.

If you see unexpected successful logins to admin accounts, don’t assume it was a mistake. Assume the device is compromised and consider replacing it, because the attackers may have already modified its configuration or planted backdoor accounts that persist through credential rotation.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FortiBleed)

  • ✇Security Affairs
  • FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls Pierluigi Paganini
    FortiBleed: Admin Passwords for 75,000 Fortinet Firewalls Are Out in the Wild. Half the Internet-Facing Fortinets on the Planet. Security researcher Bob Diachenko found a server sitting open on the internet containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for tens of thousands of organizations. He posted about it on LinkedIn. Kevin Beaumont, one of the most trusted independent voices in network security, then obtaine
     

FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls

18 de Junho de 2026, 04:31

FortiBleed: Admin Passwords for 75,000 Fortinet Firewalls Are Out in the Wild. Half the Internet-Facing Fortinets on the Planet.

Security researcher Bob Diachenko found a server sitting open on the internet containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for tens of thousands of organizations. He posted about it on LinkedIn. Kevin Beaumont, one of the most trusted independent voices in network security, then obtained the dataset, worked through it with Hudson Rock, and confirmed what nobody wanted to hear.

“Massive Fortinet/FortiGate bruteforce/active exploitation campaign uncovered in action. Thousands of top vendors instances are listed in the files like this (see screenshot). This one alone has 21,634 domain names – from Chevron to Fortinet itself. All – with potentially working passwords to the FortiGate appliances obtained through various menas.” Bob Diachenko wrote on LinkedIn.
“Crooks use sophisticated hashcracking approach to get then plaintext passwords from the Fortigate configs and use them consequently in the internal network movement and takeover.”

The popular cybersecurity expert Kevin Beaumont confirmed that the data is legit and is related to around 75k devices.

“The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data.” reads the analysis published by Beaumont. “The data appears to have come from exports of config from the devices, as it includes things which are only visible from the device itself.”

Beaumont verified credentials at multiple organizations in the dataset personally and found them working. The IP addresses in this collection are largely different from the 2025 Belsen Group leak, which covered 15,000 devices. That earlier dump was old data from a 2022 zero-day. This one isn’t.

Based on Shodan polling, the FortiBleed dataset covers roughly 50% of all Fortinet firewall devices currently facing the internet.

“In a majority of cases, the Fortigate Management Interface is exposed to the internet on impacted devices.” states the expert.

According to Hudson Rock’s analysis, the 73,932 unique firewall URLs span 194 countries and 21,632 unique domains. Names appearing in the dataset according to Hudson Rock include Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and numerous government agencies and critical infrastructure operators. One entry in Diachenko’s screenshots alone listed 21,634 domain names, including Chevron and Fortinet itself.

Diachenko’s investigation went further after he found the attackers had accidentally left an open directory containing their own tooling, scripts, connection strings, logs, and analytics. What he found inside suggests a Russian-speaking multi-operator threat group conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets, plus 2.1 billion attempts against 163,650 Microsoft SQL Server systems.

The group reportedly intercepted SSL VPN authentication hashes and cracked them using a 45-GPU cluster managed through Hashtopolis. Multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey were described as fully compromised, including a Turkish NATO defense contractor from which classified documents were allegedly stolen.

The data appears to have come from exported device configurations rather than a simple credential scrape. That’s a meaningful distinction: config exports contain information you can’t get just by intercepting login traffic, which points toward actual device access at some point. How that access was obtained remains unknown: it may be one of the many documented Fortinet CVEs, or it may be something new.

One detail in the dataset that stands out is the business intelligence layer. Each entry includes the company’s industry, revenue, employee count, and country, formatted in a way Beaumont describes as very common in criminal markets for selling initial access. This wasn’t assembled for personal use. It was assembled for sale or coordinated deployment across a team. The attached comments on each target are essentially a sales catalog.

That means an attacker with these credentials can log in remotely, gain access to the firewall and therefore the network behind it, change security settings, and create backdoor admin accounts. Beaumont also noted that Fortinet moved to PBKDF2 credential storage in early 2025 firmware updates, but only for devices where admins had actually logged in after applying the update. Many devices were still storing passwords as SHA-256 with salt, which is crackable via brute force from a stolen config file.

Hudson Rock has published a free lookup tool at hudsonrock.com/fortinet where organizations can check if their domain appears in the dataset.

” It is unclear where Hunt Intelligence obtained the data from and how long it has been in circulation, however it is formatted in a way which looks like an eCrime gang — e.g. it lists the type of company, their revenue and country.” concludes Beaumont. “This is a very common format in eCrime circles when selling initial access information.”

For any organization that finds itself in the data: rotate admin credentials immediately, check for unexpected successful logins to admin accounts, upgrade to the latest FortiOS and have admins log back in to trigger the credential storage upgrade, disable internet-facing management interfaces, and enforce multi-factor authentication on all admin users.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FortiBleed)

FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries

Researchers say FortiBleed used stolen and tested credentials to access exposed Fortinet firewalls, putting major organizations and public agencies at risk now.
❌
❌