🚨 FortiBleed – 70,000+ Fortinet Firewalls Compromised in Massive Exploitation Attack
Source: https://t.co/lVtJOueGaF
An exhaustive cyber espionage campaign now dubbed "FortiBleed" has silently compromised over 73,932 unique Fortinet firewall URLs across 194 countries.
Threat actors executed an estimated 1.16 billion credential-based attempts against over 320,000 FortiGate targets, while simultaneously launching an additional 2.1 billion brute-force attempts against more than 160,000 MSSQL servers, resulting in 21,632 unique compromised domains.
This campaign is attributed to a multi-operator, Russian-speaking cybercriminal group whose methodology goes well beyond simple credential stuffing.
#cybersecuritynews
‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots.
Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy.
▪️ AI surfaces a massive wave of 0-day RCEs.
▪️ Submissions overwhelm ZDI past max capacity.
▪️ Slots run out. Researchers with working chains get rejected.
▪️ "Revenge disclosures" begin. ← we are here.
Confirmed casualties so far:
▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land.
▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla.
▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere.
▪️ @ryotkak : tried to register for 3+ weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel.
▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected.
▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected.
Reported impact: a community-estimated 150+ researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in.
ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
@guffanti_marco L'ignoranza becera di post come questi mi lascia interdetto ogni volta. Almeno informati prima di scrivere qualcosa, no? Specie sugli orologi.
🔥 New from @philofishal , @syrion89 and @TomHegel:
🇰🇵 BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence
https://t.co/t2zC6uM4LM
Guys, I started working at the cybersecurity firm Crowdstrike. Today is my first day. Eight hours ago, I pushed major code to production. I am so proud of myself. I am going now home. I feel something really good is coming my way tomorrow morning at work 🥰🧑🏻💻
@Kiarup Vai di altri canali. Io oramai sto eliminando tutto o passando a piani più economici con pubblicità (Netflix).
D+ è stato il primo eliminato, toccherà a fine anno a Paramount che uso pochissimo.
This is CrowdStrike's Director of Overwatch, so I hope to help spread the word. I believe CS stopped these changes from being pushed out so machines late to the party wont get the faulty driver.
Command in Safe Mode:
del "C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys"
🚨CrowdStrike - Massive Outage Globally 🚨
The latest CrowdStrike update is causing a widespread issue resulting in a Blue Screen of Death (BSOD) boot loop globally.
Many users are experiencing major outages due to this problem
https://t.co/wD9TJoMDlu
#CrowdStrike
Quindi sono violente delle ragazze che manifestano contro una ministra e non dei governanti che aprono le porte agli antiabortisti nei consultori? Il mondo al contrario.