logo

FortiBleed – 70,000+ Fortinet Firewalls Compromised in Massive Exploitation Attack

ID: d5d5f27e-f655-5e7a-996e-a9418f90e9ff

STIX ID: report--d5d5f27e-f655-5e7a-996e-a9418f90e9ff

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Guru Baran

...
...

A global, industrial-scale cybercriminal campaign dubbed "FortiBleed" has compromised over 73,900 Fortinet firewall URLs across 194 countries, executing ~1.16 billion credential-based attempts against FortiGate targets and ~2.1 billion brute-force attempts against MSSQL servers; operators used infostealer-harvested credentials and offline hash cracking (45-GPU Hashtopolis) to gain persistent AD access and exfiltrated sensitive documents from multiple organizations, including a Turkish NATO contractor. Immediate mitigations recommended include forced credential rotation, universal MFA on external gateways, log auditing, and restricting management interface exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.