importantSYS.SOURCE: The Hacker News• 2026-10-07T17:26:56+05:30
FBI Warns of Ongoing FortiBleed Campaign Targeting Fortinet Devices with 86,644 Credentials Compromised
The FBI and USSS warn of an active FortiBleed campaign exploiting Fortinet devices, having compromised 86,644 credentials through credential stuffing and password spraying. The attack enables ransomware deployment and requires immediate mitigation to prevent persistent access and data exfiltration.
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways.
"The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
*** END OF TRANSMISSION ***