FortiBleed: 74,000 Admin Credentials Cracked From Devices That Were Already Patched
ID: a2c946aa-9130-5fc6-a6eb-4c287b48e3a7
STIX ID: report--a2c946aa-9130-5fc6-a6eb-4c287b48e3a7
Feed Name: Security Boulevard
Researchers disclosed that attackers collected FortiGate configuration backups stolen via earlier vulnerabilities and used GPU clusters to crack over 74,000 admin credentials; many devices had been patched but administrative passwords were not rotated, so the compromise persisted. The report frames this as the fourth distinct Fortinet security event in 2026, highlights that patching without credential rotation is insufficient, and recommends immediate rotation of FortiGate admin credentials, phishing-resistant MFA, systematic fleet audits, and treating configuration backups as highly sensitive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
