logo

FortiBleed Campaign Used Custom FortiGate Sniffer to Steal Credentials

ID: dd2fb407-631f-5188-a57e-b67941e08ae9

STIX ID: report--dd2fb407-631f-5188-a57e-b67941e08ae9

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-06-22

Date Updated: 2026-06-24

...
...

SOCRadar's analysis describes the FortiBleed campaign, where attackers exploited FortiGate vulnerabilities to deploy custom, stealthy packet sniffers that parse FortiOS session formats and exfiltrate administrative and VPN credentials at scale; Fortinet has released patches and IOCs, and organizations are advised to patch, rotate credentials, audit logs, and implement segmentation and integrity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.