FortiBleed: You Cannot Patch a Valid Login by Lucie Cardiet
ID: beeaa392-8f0b-5329-84f3-6146d5745253
STIX ID: report--beeaa392-8f0b-5329-84f3-6146d5745253
Feed Name: Vectra AI Blog
A researcher discovered a leaked catalogue of validated usernames and passwords for tens of thousands of internet-facing Fortinet firewalls (approximately 86,644 devices across 194 countries) assembled by a brokered criminal campaign called FortiBleed/SantaAd; attackers used large-scale brute force, reused leaked credentials, and GPU cracking to gather credentials, then validated, ranked by target value, and auctioned access to ransomware/extortion groups—creating widely usable legitimate logins that are difficult to detect because they appear as normal successful authentications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
