A campaign dubbed FortiBleed has exposed administrative and VPN credentials for over 73,000 FortiGate systems. The compromised data has been offered for sale by at least two threat actors, one of whom is considered credible by researchers, while the other is suspected of attempting to re-extort victims. The exposed credentials impact organizations across various sectors, including government and critical infrastructure.

A campaign dubbed "FortiBleed" has exposed administrative and VPN credentials for an estimated 73,932 FortiGate firewall systems globally. The compromised data, reportedly originating from a Russian-speaking threat group, has impacted organizations across critical sectors including government, telecommunications, financial services, healthcare, manufacturing, and multinational corporations.
Security researcher Volodymyr Diachenko first reported on the dataset on June 13, 2026, attributing it to a Russian-speaking threat actor. Subsequent analysis by cybersecurity researcher Kevin Beaumont and threat intelligence firm Hudson Rock validated portions of the dataset, with Beaumont confirming the authenticity of sampled administrative credentials. Many of the affected devices were reportedly still online and running recent versions of FortiOS, with their management interfaces exposed to the internet at the time of disclosure.
The scale of the exposure is significant, with the dataset allegedly containing credentials for systems in 194 countries. Confirmed or reported compromises include organizations in Japan, Taiwan, Vietnam, Iraq, and Türkiye. Notably, a Turkish NATO defense contractor is among those affected, with threat actors allegedly exfiltrating classified documents from the compromised system.
According to Diachenko's investigation, the threat actors conducted approximately 1.16 billion credential attempts against FortiGate targets and an additional 2.1 billion attempts against Microsoft SQL Server systems. They reportedly intercepted SSL VPN authentication hashes and utilized a 45-GPU cluster managed through Hashtopolis to crack these hashes, recovering plaintext credentials. Researchers believe the dataset likely originated from exported FortiGate configuration files, allowing for offline credential recovery without continuous access to the targeted devices.
Threat intelligence firm Insikt Group identified malicious activity associated with the IP address 85.11.187.8, linked to the FortiBleed attacks. Their analysis revealed artifacts consistent with credential harvesting and intrusion activities, including a sniffer log for Fortinet credential capture, cracking orchestration files, Active Directory enumeration scripts, password-spraying tools, and SMB/DFS collection scripts with exfiltration capabilities. Evidence of log-clearing markers was also present, suggesting attempts to cover tracks. A PwnDefend blog post on June 18, 2026, corroborated the association of this IP address with the campaign.
The FortiBleed campaign is considered high-priority due to the independently verified authenticity of a subset of credentials, the ongoing exposure of many affected devices, and the sheer scale of the incident. The attribution to a Russian-speaking group and the confirmed targeting of a NATO defense contractor raise concerns about potential espionage objectives.
The timeline of events began on June 13, 2026, with Diachenko's public report. On the same day, Kevin Beaumont published his analysis confirming the credentials, and Hudson Rock validated parts of the dataset, releasing a lookup tool for organizations to check for exposure.
Insikt Group also noted that at least two threat actors are attempting to profit from the FortiBleed data. One seller, operating under the moniker "SantaAd" on an exploit forum, advertised auctioning 34,000 lines of FortiGate VPN data on June 12, 2026. Insikt Group assesses this seller as likely credible, though they did not observe a sample to confirm it was the same data involved in the FortiBleed incident.
A second seller, identified as "shinymontanna" within a public Telegram channel and leveraging the ShinyHunters branding, was identified on June 21, 2026. This seller is reportedly reusing language from SantaAd's post and is assessed by Insikt Group as likely attempting to re-extort victims, a tactic they have employed previously. Shinymontanna has been active since at least late 2025, engaging in extortion attempts with ransom demands ranging from $100,000 to $2 million.
Organizations running Fortinet products are advised to immediately rotate all FortiGate administrative and SSL VPN credentials. They should also enforce multi-factor authentication for all remote and administrative access, review Fortinet logs for suspicious activity, and consider replacing devices with confirmed suspicious activity. Restricting internet exposure for management interfaces, patching FortiOS, and reviewing hardening settings are also recommended. Furthermore, organizations should hunt for downstream compromise within their networks if exposed credentials were in use.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed