The Jerusalem PostTurkey sending technical, defensive support to Saudi Arabia to help fight Houthis, officials sayESPNAre Texans and Chargers this bad? How should we bet the Rams?ESPN DeportesGurú de las Diagonales: El misterio en torno a Drake MayeBollywood HungamaSCOOP: Ramayana expected to have paid previews on November 4; Godzilla Minus Zero to get limited showcasing in IMAX in IndiaDaily MaverickLABOUR ABUSE: New report exposes the exploitation behind the world’s food systems workersInquirerMan nabbed after surrendering unlicensed firearm in Oriental MindoroZDF heuteEntdecken Sie das ZDF-NachrichtenstudioThe South AfricanSaleng spotted back in Sundowns training ahead of Pirates showdownBBC Sport'Draining' few days for Gauff after online racist abuse01netAmazon éclate le prix de ce PC portable Dell : -45% pour finir le Prime Day en beautéRai NewsCile, cane randagio salvato dalla piena del fiume MapochoSBS 뉴스"우리 대응에 북한 당황"…"지뢰 제거, 단호한 대응이냐"
The Daily Newsstand · Free, Always
Wednesday, October 7, 2026

FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks

Translate

Tens of thousands more victims and more ransomware groups getting in on the act

The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls.

The agencies published a joint advisory on Tuesday, citing SOCRadar's verification of more than 86,644 compromised devices across 194 countries.

"Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," their advisory [PDF] states.

REG AD

"During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment."

REG AD

The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways. Criminals use credentials from earlier breaches and infostealer logs for credential stuffing and password spraying, then extract password hashes from compromised devices and crack them offline using GPU-accelerated clusters.

The agencies urged organizations to restrict internet-facing management access, terminate active administrative and VPN sessions, reset passwords, and enable phishing-resistant multi-factor authentication.

The advisory also links FortiBleed to ransomware campaigns, saying initial access brokers supplied compromised-network access to ransomware affiliates. The Register previously reported on the connection, identified by SOCRadar.

The current evidence points to affiliates working for the INC/Lynx and Payload ransomware groups making use of the credentials, and SOCRadar said in July that it had seen at least 12 confirmed ransomware attacks stemming from FortiBleed.

The agencies encouraged victims to report incidents, while noting that organizations were not obliged to provide information in response to this advisory.

The FBI and the Secret Service said victim reports could help identify indicators of compromise and warned against paying ransoms. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.