Over 68,000 Exposed Firewalls.
The @quimerax_intel analyzed the FortiBleed dataset and cross-referenced it with the historical Belsen Group leak associated with the exploitation of CVE-2022-40684 in Fortinet devices.
By consolidating both datasets, we were able to identify not only devices exposed in the recent FortiBleed campaign, but also firewalls that have remained exposed across multiple years.
Our findings revealed:
• 68,732 unique IP addresses in the FortiBleed dataset (2026)
• 15,469 unique IP addresses in the Belsen Group leak (2022)
• 83,676 unique IP addresses in the combined dataset
• 525 IP addresses appearing in both leaks
These 525 devices represent the highest-risk category.
They were compromised during the 2022 campaign and still appeared in exposure data collected in 2026, suggesting a potential multi-year exposure window.
We also identified more than 350 (+600creds) Brazilian organizations appearing in the analyzed data.
To help organizations assess their exposure, QuimeraX provides a free lookup tool that allows security and infrastructure teams to search by both public firewall IP address and domain.
Check whether your organization has been affected:
https://t.co/QOPhrErRTK
We have just shared the exploit code for the IngressNightmare vulnerability (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974) at the Github: https://t.co/FPRQwOiABs
Our team has just successfully reproduced the IngressNightmare vulnerability (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974) and created a custom exploit achieving RCE.
It's a Pre-Auth RCE affecting Ingress NGINX that allows complete cluster takeover. We'll share our exploit soon.
In the original post from the Wiz team, they didn't mention the path traversal technique used to load a malicious library via /proc.
@HakaiOffsec @quimerax_asm