🚨 FortiBleed Attack Hit 430,000+ FortiGate Firewalls, Stealing 110M+ Credentials
Source: https://t.co/NXMEWEprGB
A large-scale, ongoing credential-harvesting campaign dubbed "FortiBleed" has silently compromised more than 430,000 FortiGate firewalls globally, siphoning over 110 million credentials directly from live network traffic since at least February 2026.
At the heart of the operation is a custom-built Golang tool called FortiGateSniffer, designed to monitor 24 network protocols simultaneously and parse authentication data from intercepted network flows.
At the time of analysis, more than 80,553 FortiGate devices and 23,406 unique domains were implicated, with active sniffing still observed on over 19,000 firewalls.
#cybersecuritynews
‼️ Just in: FortiBleed attackers rented 36 enterprise GPUs from an AI cloud provider to crack stolen FortiGate configuration hashes at industrial scale.
Cheap, on-demand GPU compute has quietly made mass password cracking easy, while tens of thousands of organisations still run VPN firewalls with no MFA. The threat is now less likely a nation-state and more like a financially motivated crew with a credit card and rented hardware in the cloud.
A write-up by Kevin Beaumont shines a light on the campaign that cracked credentials for tens of thousands of Fortinet firewalls.
He disputes Fortinet's public line that the data is just old breaches and bruteforcing, noting it contains freshly cracked passwords and that every organisation he helped had its config exported in the past month. In those cases the attacker went well beyond collecting credentials, adding admin accounts, opening SSH and RDP firewall rules, and logging into IPsec tunnels, with CloudSEK assessing around a thousand organisations breached internally and the attacker reaching internal Active Directory at a number of telcos and managed service providers.
We shared a one-off "FortiBleed" dataset of compromised Fortinet devices in our Compromised Website Report https://t.co/D1KZAGvNIZ thanks to collaboration with @socradar!
Stats:
Dashboard World map view:
https://t.co/34HZSWCwd3
Dashboard Tree map view:
https://t.co/8aZBMnT20I
🛑 FortiGate credentials are now the attack path.
CISA is urging Fortinet customers to secure internet-facing FortiGate appliances after FortiBleed activity tied to credential attacks.
The number of compromised devices stands at 86,644 as of June 19, 2026.
Reset passwords. Kill active sessions. Enable MFA.
Read - https://t.co/GFlhSAcR0f
🚨 BrEaKiNg: Splunk, a security product, has zero authentication in its built-in database service and accepts any credentials, according to the security researchers who just dropped a full pre-auth RCE chain for Splunk Enterprise (CVE-2026-20253, CVSS 9.8).
Splunk Enterprise on AWS is vulnerable out of the box.
96% of security teams can’t confirm if risks are exploitable.
In this analysis, Jean-Philippe Salles of @FiligranHQ shows CTEM is failing at prioritization and validation, with 42% of SOC time wasted on low-value work.
The gap is poor use of threat intelligence.
🔗 Why CTEM breaks without intel-driven context → https://t.co/GEpC4HIlEB
⚠️ FortiOS Authentication Bypass Vulnerability Lets Attackers Bypass LDAP Authentication
Source: https://t.co/GLWZL6S5bz
Fortinet has disclosed a high-severity authentication bypass vulnerability in FortiOS, tracked as CVE-2026-22153 (FG-IR-25-1052), that could allow unauthenticated attackers to sidestep LDAP authentication for Agentless VPN or Fortinet Single Sign-On (FSSO) policies.
The flaw resides in the fnbamd daemon and requires specific LDAP server configurations enabling unauthenticated binds. The issue stems from improper handling of LDAP authentication requests.
An attacker could exploit this under certain setups, such as those permitting anonymous binds, to gain unauthorized access without valid credentials.
#cybersecuritynews #vulnerability
🛑 Cisco released patches for CVE-2026-20029 in Identity Services Engine and ISE-PIC.
The XML parsing flaw allows an authenticated admin to upload a malicious file and read restricted OS files.
A public PoC exists. Patch Now.
🔗 Read → https://t.co/91DPdDkPKc
Cybercrime shifted in 2025. 70.5% of data breaches hit SMBs, not large enterprises.
Attackers moved to smaller firms after big companies hardened defenses and rejected ransoms. Volume replaced payout size.
🔗 What the data shows from 2025 breaches → https://t.co/wF6vDEGJbe
🚨 Cisco warns hackers are targeting unpatched Secure Firewall ASA & FTD devices with a new attack variant exploiting two flaws — CVE-2025-20333 and CVE-2025-20362.
The attacks can crash devices (DoS) or let attackers run code as root.
Details here ↓ https://t.co/0j9vmw878Y
Apple backports a critical fix for CVE-2025-43300—already used in a sophisticated spyware attack.
🕵️♂️ Hackers chained it with a WhatsApp flaw to target fewer than 200 people.
📱 Older iPhones & Macs are now patched—don’t skip this update.
Details → https://t.co/7evXBzAMt7
🛑 New Cisco flaw scores a perfect 10.0 CVSS.
A hardcoded token. Root access. No login needed.
If you run Catalyst 9800 wireless controllers, you’ll want to check this fast.
👉 Read more about CVE-2025-20188 here: https://t.co/ZTtk1qHqoQ
Rebooting #ISE? #DYK: with Cisco ISE 3.4, the reboot time will be cut by 40%! ➡️ https://t.co/GWThTA3gwx
While that's a win for efficiency, you might have to savor your coffee break a bit quicker. ☕️ 😅
🏆 🤩 DNS-layer #security is simple to deploy, easy to manage – and Cisco is proud to be named a @GigaOm Radar leader in the #DNS vendor space!
Read the report 📄: https://t.co/EHfFFkdM9q
The most common kill chain used during a ransomware incident typically involves several stages, which may include:
1. **Reconnaissance**: Attackers gather information about the target network, such as identifying vulnerabilities, employee email addresses, or system configurations.
2. **Initial Access**: This involves the actual breach of the network, often through methods like phishing emails, exploiting unpatched software vulnerabilities, or through compromised credentials obtained from previous data breaches.
3. **Lateral Movement**: Once inside the network, attackers move laterally to gain access to additional systems and resources. They may exploit weak access controls or use stolen credentials to move between machines.
4. **Privilege Escalation**: Attackers attempt to gain higher levels of access within the network, often by exploiting vulnerabilities in software or misconfigurations to elevate their privileges.
5. **Data Exfiltration**: In some cases, attackers may exfiltrate sensitive data before deploying ransomware, which can be used as leverage to increase the likelihood of payment.
6. **Deployment of Ransomware**: After establishing a foothold and ensuring they have the necessary access, attackers deploy the ransomware payload across the network, encrypting files and demanding payment for decryption keys.
To defend against these stages of the kill chain, you can implement a range of security measures, including:
- **User Education**: Train employees to recognize phishing attempts and other social engineering tactics.
- **Patch Management**: Keep software and systems up to date with the latest security patches to mitigate known vulnerabilities.
- **Access Control**: Implement strong access controls, including the principle of least privilege, to limit the ability of attackers to move laterally within the network.
- **Network Segmentation**: Segment your network to limit the spread of ransomware in case of a breach.
- **Monitoring and Detection**: Employ robust monitoring and detection tools to identify suspicious activity within the network.
- **Backup and Recovery**: Regularly backup critical data and ensure backups are stored securely offline to prevent them from being encrypted by ransomware.
- **Incident Response Plan**: Develop and regularly test an incident response plan to ensure a swift and effective response in the event of a ransomware attack.
By focusing on these areas, you can significantly reduce the risk of a successful ransomware attack on your network.
La arquitectura Infinity de Check Point proporciona ciberseguridad consolidada de quinta generación en redes, nubes y entornos móviles.
Conoce más
https://t.co/VzbrCbCmrh
#TransformaciónDigital#InnovaciónEmpresarial
En #Atria, contamos con un equipo humano con conocimiento, experiencia y especialización en soluciones de redes corporativas para la transformación digital. Descubre más con tu Ejecutivo de Cuenta.
https://t.co/O0ZNi5wLP4
#Cisco#Teletrabajo#TrabajoRemoto