[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fL_oFgGwKfjmbYdY7oNb-e8P6ed4m8P_oK57G29zsK88":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"4196f065-11ba-4460-9a5f-dd59a9ff96ee","FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials","fbi-warns-fortibleed-remains-active-after-amassing-86-644-fortinet-device-creden-98f167","The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. \"The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat","The FBI and Secret Service have issued a warning that the FortiBleed campaign is still active, targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. This campaign exploits reused or leaked credentials and legacy password storage to harvest and crack authentication data, with over 86,000 credentials already compromised. The attackers deploy a Go-based tool to intercept traffic and use a GPU-accelerated cluster for offline password cracking, facilitating lateral movement and data exfiltration.","FBI warns FortiBleed campaign remains active, stealing Fortinet device credentials.","FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials Ravie LakshmananOct 07, 2026Cybercrime \u002F Network Security The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. \"The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale,\" the agencies said. \"Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials.\" FortiBleed was first documented by SOCRadar in Hudson Rock in June 2026, with the activity targeting thousands of Fortinet firewalls as part of a global campaign. In all, the Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026. The campaign subsequently prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to urge Fortinet customers with FortiGate appliances to enable phishing-resistant authentication, terminate active SSL VPN and administrative sessions, reset Fortinet VPN and administrative passwords, use the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials, and review logs for signs of suspicious activity. FortiBleed is a five-stage campaign that conducts widespread reconnaissance to identify exposed portals, gain access to those devices using credential stuffing and password spraying based on data obtained from prior leak dumps and infostealer logs, and then deploy a Go-based tool called FortigateSniffer to passively intercept authentication traffic across 24 protocols and harvest credentials and password hashes. The password hashes are then routed to a GPU-accelerated cracking cluster that uses Hashmat and Hashtopolis for offline cracking, after which they are used to facilitate lateral movement, Active Directory enumeration, Kerberos validation, and SMB authentication. In the final stage, sensitive data from network shares is exfiltrated while stolen session cookies are used to maintain persistent, authenticated access. \"Cracked credentials were enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure,\" the agencies said. \"New administrative accounts were created on the firewall to maintain persistence.\" With the verified credentials in hand, the attackers have been found to move deeper into victim environments, conduct enumeration, and conduct password spraying to expand access and identify privileged accounts. In addition, the initial access is used to add new accounts to the system as a way of maintaining persistence on the appliance. Some of the commonly identified compromised account names is listed below - adminin fortiAdmin forticloud-sync admin fgtsecure pakedge forticloud-tech districtadmin system_config gttadmin roadmin itadmin Technical_support adminsslvpn IT_Manager my_admin support_fortinet fgtsec forti_support2 The adversary is suspected to be an initial access broker that packages the stolen information and sells it to downstream threat actors. This is evidenced by the fact that operator overlaps tying FortiBleed to INC and Lynx ransomware operations, likely indicating that the access is being abused for ransomware deployment. \"Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system,\" the FBI and USSS warned. \"During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment.\" If potential compromise is detected, organizations are advised to isolate the affected devices, collect necessary artifacts and logs, report the incident to the FBI and USSS, and apply relevant countermeasures to mitigate the threat. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cybercrime, data breach, Fortinet, Malware, network security ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Ffbi-warns-fortibleed-remains-active.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgQZeKQIcHTVLgqnHpZYN73YclFawl51QxpykrKEb97sAJjA8qtN7FaUJaS0jLMeSS29cTB0nR_yFzsITX_e5SI8Xa8BfM1LDOGsEEEpDmVC8YNqOcEYEuep1UbHovyLlxrwRmYZ3FrbaaKq9eKwICiUTkkPleIibOHdWnbV5cpwYPCrHQasrTxVFA9seQ-\u002Fs1600\u002Fforti-admin.jpg","2026-10-07T11:56:56+00:00","2026-10-07T14:00:03.504292+00:00",9,[18,21,24,26,29],{"name":19,"type":20},"Fortinet","vendor",{"name":22,"type":23},"FortiGate","product",{"name":25,"type":23},"SSL VPN",{"name":27,"type":28},"INC","threat_actor",{"name":30,"type":31},"FortiBleed","campaign","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":32,"icon":34,"name":35,"slug":36},null,"Threat Intelligence","threat-intelligence",[38,43,48],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[54],{"type":52,"value":55,"context":56},"FortigateSniffer","Go-based tool used to passively intercept authentication traffic and harvest credentials."]