FortiBleed Exposes Global Credential-Spraying Operation
ID: 63025b63-f658-5d93-a8d3-818766757e47
STIX ID: report--63025b63-f658-5d93-a8d3-818766757e47
Feed Name: Security Affairs
Threat Score
FortiBleed exposed an industrial-scale, multi-operator credential‑spraying campaign that mass‑scanned hundreds of thousands of FortiGate and Sophos endpoints and launched over a billion login attempts (and billions more against MSSQL), deployed network sniffers to harvest credentials, used a 45‑GPU cracking cluster to crack hashes, replayed VPN sessions to gain AD access, and exfiltrated sensitive data from multiple organizations across several countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
