[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:fbi-warns-fortibleed-remains-active-after-amassing-86-644-fortinet-device-creden-muzdhhia":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":16,"article_ids":17,"ioc_summary":19,"source_urls":20,"status":22,"expires_at":23,"created_at":24,"updated_at":25,"articles":26},"088f23f6-e86b-4624-8719-206111f85c80","FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials","fbi-warns-fortibleed-remains-active-after-amassing-86-644-fortinet-device-creden-muzdhhia","FortiBleed campaign continues harvesting credentials from internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Over 86,644 credentials have been compromised through exploitation of reused\u002Fleaked passwords and legacy storage mechanisms. Attackers use these credentials for lateral movement and data exfiltration.","critical","advisory",[],[13,14,15],"Fortinet","FortiGate","SSL VPN","Immediately audit all Fortinet FortiGate and SSL VPN gateway devices for exposed internet access. Reset all administrative and service account credentials on affected systems. Hunt for Go-based traffic interception tools and evidence of lateral movement from compromised Fortinet devices.",[18],"4196f065-11ba-4460-9a5f-dd59a9ff96ee",null,[21],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Ffbi-warns-fortibleed-remains-active.html","active","2026-10-10T10:07:24.931+00:00","2026-10-08T10:07:27.269083+00:00","2026-10-08T10:10:05.591687+00:00",[27],{"id":18,"title":6,"url":21}]