CISA warning on FortiBleed for FortiGate customers
Public Sector Action
Summary
Hide ▲
Show ▼
CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached 86,644 compromised devices by June 19, 2026 and was targeting internet-accessible gateways and administrators. CISA directed operators to terminate active sessions, reset passwords, enforce strong password policies, and enable phishing-resistant MFA.
Related Happenings
CISA-led joint advisory on Russian router targeting
Public Sector Action
H score32
First: 14.07.2026 15:00
Last: 14.07.2026 15:00
Sources 1
About this happening:
CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...
CISA-led joint advisory on Russian router targeting
Public Sector ActionAbout this happening: CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...
Microsoft Azure CLI password-spray campaign using ROPC
Campaign
H score24
First: 01.07.2026 08:46
Last: 01.07.2026 08:46
Sources 1
About this happening:
A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
Microsoft Azure CLI password-spray campaign using ROPC
CampaignAbout this happening: A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
Initial access broker (IAB) campaign expands across multiple victims
Campaign
H score89
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Initial access broker (IAB) campaign expands across multiple victims
CampaignAbout this happening: The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Latest development: 23.06.2026 13:30
On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware Activity
H score72
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware ActivityAbout this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data Leak
H score93
First: 22.06.2026 11:30
Last: 22.06.2026 11:30
Sources 1
About this happening:
The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
FortiGate firewall and SSL VPN customers data exposed after Fortinet breach
Data LeakAbout this happening: The FortiBleed credential leak exposed around 75,000 stolen logins from FortiGate firewall and SSL VPN customers, creating immediate account-takeover risk for affected...
Timeline
-
19.06.2026 17:00 1 articles · 26d ago
Working Fortinet credentials database surfaces on exposed server
Initial DisclosureSecurity researcher Volodymyr "Bob" Diachenko discovered a server holding a database of working login credentials for thousands of Fortinet firewalls and VPN gateways across 194 countries, and SOCRadar said the same server also staged the operator's tools and automation scripts.
Show sources
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices — thehackernews.com — 19.06.2026 17:00
-
19.06.2026 17:00 1 articles · 26d ago
FortiBleed operators mass-scan Fortinet endpoints and spray stolen passwords
Exploitation ObservedThe FortiBleed operators mass-scan Fortinet remote login endpoints, spray identified devices with known login and password combinations, and then monitor traffic through compromised appliances to harvest additional credentials for further compromise.
Show sources
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices — thehackernews.com — 19.06.2026 17:00
-
19.06.2026 17:00 1 articles · 26d ago
FortiBleed compromises 86,644 FortiGate devices across 194 countries
Campaign Scope UpdateFortiBleed reached 86,644 compromised devices as of June 19, 2026, with telecom, government, and education emerging as the most impacted sectors and the largest exposures located in India, the U.S., Mexico, Colombia, and Thailand.
Show sources
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices — thehackernews.com — 19.06.2026 17:00
-
19.06.2026 17:00 2 articles · 26d ago
CISA directs Fortinet customers to reset credentials and enable phishing-resistant MFA
Mitigation Patch UpdateCISA directed Fortinet customers to terminate active SSL VPN and administrative sessions, reset Fortinet VPN and administrative passwords, enforce strong password policies, enable phishing-resistant MFA, and reduce the attack surface, while Fortinet said PBKDF2-based password hashing in FortiOS 7.2.11, 7.4.8, and 7.6.1 replaces the legacy SHA-256-based storage mechanism.
Show sources
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices — thehackernews.com — 19.06.2026 17:00
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices — thehackernews.com — 19.06.2026 17:00