logo

What the Fortibleed campaign means for organizations running FortiGate firewalls

ID: 076a74c9-26f5-5435-9418-4478e0fa809c

STIX ID: report--076a74c9-26f5-5435-9418-4478e0fa809c

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

Author: Zeljka Zorz

...
...

Researchers uncovered a large, automated credential-harvesting campaign against internet-exposed FortiGate management interfaces and SSL VPNs that used leaked/compromised credentials and brute force to intercept authentication traffic, extract hashes, and crack them using rented GPU resources. Attackers created stealthy admin accounts, pivoted via VPNs into internal networks using tools like Impacket and OpenFortiVPN, conducted AD audits and file-spidering to harvest more credentials, and left artifacts and lists of compromised devices; organizations are advised to check FortiBleed datasets, rebuild affected devices, rotate credentials and MFA, remove exposed management interfaces, and audit AD for lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.