Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Brokers Exploit FortiGate Firewalls in Cyber Campaign

Russian Brokers Exploit FortiGate Firewalls in Cyber Campaign

Posted on June 23, 2026 By CWS

Russian cyber actors have been identified as the culprits behind a significant security breach targeting FortiGate firewalls worldwide. Known as the FortiBleed campaign, this operation has jeopardized over 430,000 firewalls, as reported by SOCRadar.

Understanding the FortiBleed Campaign

The FortiBleed credential-harvesting campaign, which came to light last week, traces back to February. Initially thought to affect only Fortinet products, it has since been revealed as a broader multi-vendor attack. SOCRadar’s detailed analysis attributes the campaign to financially motivated cybercriminals operating through a complex credential and access harvesting operation.

According to SOCRadar, the attackers infiltrate exposed firewalls to capture authentication data, which they then sell. This campaign has affected over 80,000 identified targets, with more than 19,000 still under surveillance using a custom tool called FortigateSniffer.

Tools and Techniques of the Attackers

The investigation by SOCRadar has unveiled hundreds of servers and more than 650 credential-harvesting pipelines involved in the operation. It’s estimated that these efforts have compromised over 110 million credentials. The attackers use tools like Masscan and Shodan to identify vulnerable devices, which are then compromised through SSH brute-force attacks.

Once access is gained, network sniffers are deployed to capture credentials and password hashes, which are cracked and used for further infiltration into Active Directory domains and other network services. Sensitive data is exfiltrated, and stolen session cookies ensure persistent access to compromised systems.

Implications and Future Outlook

The FortiBleed campaign poses a significant threat, particularly because firewalls are crucial network security components. The campaign also impacts supply chains, targeting Managed Service Providers (MSPs) and IT firms managing Fortinet devices. The campaign predominantly targets small and medium-sized businesses across various sectors, with a notable focus on the United States and India.

SOCRadar has also discovered two major credential sources used by the attackers. One source aggregates data from previous breaches alongside purchased datasets, while the other is tailored specifically for FortiGate admin accounts. The campaign’s severity was highlighted on June 15 when Kerberos hashes were cracked, leading to the exfiltration of sensitive data from a NATO-aligned defense contractor.

The potential collaboration between the Russian-speaking initial access broker and state-sponsored groups raises concerns about future attacks. As the campaign evolves, organizations must enhance their cybersecurity measures to protect against such threats.

Security Week News Tags:credential harvesting, cyber threats, Cybersecurity, firewall vulnerabilities, FortiBleed, Fortigate, Fortinet, network security, Russian hackers, SOCRadar

Post navigation

Previous Post: Malicious npm Packages Exploit PostCSS Tools for Windows RAT
Next Post: Hackers Exploit M365 Accounts for Advanced Phishing Tactics

Related Posts

Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks Security Week News
In Other News: PoC for Fortinet Bug, AI Model Subverts Shutdown, RAT Source Code Leaked In Other News: PoC for Fortinet Bug, AI Model Subverts Shutdown, RAT Source Code Leaked Security Week News
Ransomware Attack Forces Kettering Health to Cancel Procedures Ransomware Attack Forces Kettering Health to Cancel Procedures Security Week News
Red Hat Confirms GitLab Instance Hack, Data Theft Red Hat Confirms GitLab Instance Hack, Data Theft Security Week News
New BootROM Exploit Threatens iPhone Security New BootROM Exploit Threatens iPhone Security Security Week News
Navia Data Breach Affects Millions Navia Data Breach Affects Millions Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised
  • Trump Boosts Post-Quantum Cryptography Efforts with New Order
  • Federal Push for Post-Quantum Security by 2030

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised
  • Trump Boosts Post-Quantum Cryptography Efforts with New Order
  • Federal Push for Post-Quantum Security by 2030

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark