Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FBI Alerts on Persistent FortiBleed Threat to Fortinet Devices

FBI Alerts on Persistent FortiBleed Threat to Fortinet Devices

Posted on October 7, 2026 By CWS

The U.S. Federal Bureau of Investigation (FBI) and the Secret Service have issued a warning regarding the ongoing cyber threat posed by the FortiBleed campaign. This malicious activity targets Fortinet FortiGate firewalls and SSL VPN gateways, exploiting reused or leaked credentials alongside outdated SHA-256 password storage methods. Such tactics allow cybercriminals to harvest and crack authentication data on a large scale.

Details of the FortiBleed Campaign

The FortiBleed operation, first identified by SOCRadar in June 2026, has been actively targeting thousands of Fortinet devices worldwide. The campaign, primarily attributed to Russian-speaking actors, has reportedly acquired over 86,644 device credentials across 194 countries by mid-June 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has advised Fortinet users to adopt phishing-resistant authentication, reset passwords, and monitor for unusual activity.

FortiBleed comprises five stages, beginning with reconnaissance to identify vulnerable systems. It employs credential stuffing and password spraying techniques to gain access, followed by the use of a tool named FortigateSniffer to capture authentication traffic. The stolen password hashes are processed using advanced cracking techniques, enabling further infiltration into networks through lateral movement and data exfiltration.

Impact and Persistence of Attacks

With validated credentials, attackers can deeply embed themselves within victim networks, creating new accounts and conducting enumeration to broaden their access. Commonly compromised account names include ‘adminin’, ‘fortiAdmin’, and ‘forticloud-sync’. These actions ensure attackers maintain persistent access and continue to exploit compromised systems.

The perpetrators, suspected to be initial access brokers, sell stolen data to other threat actors, possibly for ransomware deployment. Associations with INC and Lynx ransomware operations suggest such transactions. Victims may find themselves locked out of their systems if attackers modify or remove original accounts.

Preventive Measures and Recommendations

Organizations that detect potential compromises are urged to isolate affected devices and gather relevant logs and artifacts. Reporting incidents to the FBI and USSS is crucial, alongside implementing countermeasures to mitigate the threat. By enhancing security protocols and monitoring for suspicious activity, organizations can better protect themselves against ongoing cyber threats.

In conclusion, the FortiBleed campaign remains a significant security concern, necessitating proactive measures to safeguard network infrastructure. Organizations are advised to remain vigilant and responsive to emerging cybersecurity challenges.

The Hacker News Tags:credential harvesting, cyber threat, Cybercrime, Cybersecurity, data breach, FBI, FortiBleed, Fortinet, IT security, network security, password security, Ransomware, security advisory, VPN

Post navigation

Previous Post: Critical Rejetto HFS Flaw Detected by Mythos AI
Next Post: Hadrian Secures $40M to Boost AI Security Platform

Related Posts

Adobe Tackles Major Security Flaws in ColdFusion and Campaign Adobe Tackles Major Security Flaws in ColdFusion and Campaign The Hacker News
Critical Flaw in Oracle WebLogic Actively Exploited Critical Flaw in Oracle WebLogic Actively Exploited The Hacker News
AI Memory Poisoning: The Threat of Hidden Prompts AI Memory Poisoning: The Threat of Hidden Prompts The Hacker News
Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More The Hacker News
Microsoft Addresses High-Severity Windows Admin Center Flaw Microsoft Addresses High-Severity Windows Admin Center Flaw The Hacker News
MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Progress DataDirect GenAI Exposes Systems
  • Georgia Power, Alabama Power Data Breach Affects 400,000
  • Critical Flaw in Atlassian Data Center Exploited Rapidly
  • Rockstar Faces Data Breaches: Source Code and Records Stolen
  • Hadrian Secures $40M to Boost AI Security Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Progress DataDirect GenAI Exposes Systems
  • Georgia Power, Alabama Power Data Breach Affects 400,000
  • Critical Flaw in Atlassian Data Center Exploited Rapidly
  • Rockstar Faces Data Breaches: Source Code and Records Stolen
  • Hadrian Secures $40M to Boost AI Security Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark