logo

An update on FortiBleed — what’s happening with victim orgs

ID: 31ace8a5-aa9a-5423-bd30-cc0e526b2a28

STIX ID: report--31ace8a5-aa9a-5423-bd30-cc0e526b2a28

Feed Name: DoublePulsar

Threat Score
82/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: Kevin Beaumont

...
...

This report updates on the FortiBleed activity: threat actors scanned and accessed internet-facing FortiGate devices, exported full device configurations, cracked stored password hashes using rented GPU clusters, and are selling/using the harvested credentials to access internal networks (including VPNs and Active Directory). The author provides observed IoCs (exporting IPs and victim lists), describes attacker actions (automated config exports, creation of admin accounts, firewall rule changes, VPN logins), and gives remediation guidance including rebuilding compromised appliances, rotating VPN keys, enforcing MFA, and firmware updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.