The images in this article were generated with artificial intelligence. How we publish
Public alert about the campaign known as FortiBleed remember that the perimeter devices - firewalls and VPN gateways - remain one of the most cost-effective and ignored routes for the attackers: thousands of exposed FortiGate have ended up with valid credentials in the hands of a Russian-speaking actor who automated the process of scanning, brute force and passive collection of passwords to quickly scale their reach.
Beyond the sensational headline, the case reveals three recurring organizational failures: the use of default accounts without renaming or rotating, the reuse of passwords and the persistence of weak credentials storage mechanisms after updates. Even when a manufacturer introduces safer hashing - in this case PBKDF2 in recent versions of FortiOS - the old hashes remain if administrators do not force a login that regenerates credentials, creating an exposure window.

The scale of the incident is instructive: the attacker first built a Verified functional credentials database using filtered combinations and then expanded it by passive traffic monitoring to capture more credentials from the compromised devices. This double cycle makes a "credimentary stuffing" campaign a self-feeding operation and much more efficient than the simple mass scanning.
The implications for operational security and business continuity are severe: compromising a firewall or a VPN concentrator is not just a technical intrusion, it is the gateway to internal networks, sensitive data and the possibility of lateral movements with valid credentials. Sectors with critical exposures such as telecommunications, public administration and education face significant regulatory risks and reputational damage if they do not act quickly.
The immediate measures recommended by agencies and to be prioritized by security teams include the completion of active administrative sessions and VPN, the restoration of all passwords of exposed devices and the implementation of robust password policies. It is also essential to force migration to PBKDF2 to store credentials and remove any legacy hash that may remain exploitable.
In parallel to technical steps, it is key to deploy compensatory defenses: to enable phishing-resistant multifactor authentication on all external and administrative interfaces, to restrict management access to segregated management networks or through jump hosts, and to reduce the exposure surface by closing unnecessary ports and services to the Internet.
Detection and response require threat hunting actions: review firewall looms, VPN, authentication and domain controllers in search of unauthorized changes, unusual connections or reconfigurations, search for compromise indicators in settings and backups, and validate that there are no persistencies such as additional administrative accounts or tunnel rules established by the attacker.

Organizations should treat such incidents as potential large-scale credentials gaps and activate incident response procedures, notification to affected parties and, if applicable, regulatory obligations. Coordination with suppliers, and consultation of official notices, helps to prioritize patches and mitigations: see the recommendations of agencies such as CISA and the manufacturer's own notices and resources in Fortinet.
In strategic terms, FortiBleed stresses the urgency of managing identity risk: inventory of administrative accounts, periodic rotation of credentials, prohibition of the re-use of passwords, use of keys and certificates where appropriate, and deployment of privileged access management (PAM). All this reduces the effectiveness of automated campaigns that rely on valid credentials.
Finally, technology and cybersecurity leaders must turn the lesson into corporate policy: demand reauthentication tests after firmware updates, audit default settings when deploying applications, and ensure that identity and access governance has both technical controls and audit processes. The basic hygiene of credentials remains, paradoxically, one of the most effective barriers to large-scale attacks.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...