[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:fbi-warns-fortibleed-campaign-still-active-hits-86-000-fortigate-devices-mv2ago9w":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":15,"article_ids":16,"ioc_summary":18,"source_urls":19,"status":21,"expires_at":22,"created_at":23,"updated_at":24,"articles":25},"bc695713-d443-4424-9b08-7bbf7972d673","FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices","fbi-warns-fortibleed-campaign-still-active-hits-86-000-fortigate-devices-mv2ago9w","FortiBleed campaign is actively targeting 86,000+ FortiGate devices worldwide using credential stuffing and password spraying with stolen credentials from previous leaks. Successful compromises result in account lockouts of legitimate admins and device reconfiguration, with confirmed links to INC Ransom, Lynx, and Payload ransomware gangs. Every compromised FortiGate is a potential pivot point for network-wide ransomware deployment.","critical","advisory",[],[13,14],"FortiGate","Fortinet","Immediately audit all FortiGate administrative accounts for unauthorized modifications, policy changes, and account lockouts. Force password resets for all FortiGate admin accounts using complex passwords not found in breach databases. Enable MFA on all FortiGate management interfaces and monitor authentication logs for credential stuffing patterns.",[17],"e28ea805-6bcc-4952-b96e-13fb33590b77",null,[20],"https:\u002F\u002Fhackread.com\u002Ffbi-fortibleed-campaign-active-fortigate-devices\u002F","active","2026-10-12T11:06:05.369+00:00","2026-10-10T11:06:09.130861+00:00","2026-10-10T11:06:26.131545+00:00",[26],{"id":17,"title":6,"url":20}]