The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An operator tied to Forti

A financially motivated cyber campaign dubbed "FortiBleed" has been linked to the INC and Lynx ransomware operations, suggesting that the credentials stolen through this activity were intended for subsequent network intrusions. This discovery highlights a coordinated effort where the initial compromise is leveraged to facilitate further malicious activities.
The FortiBleed campaign specifically targets the theft of user credentials. While the exact mechanisms of credential acquisition are not detailed, the campaign's name implies a focus on exploiting vulnerabilities or misconfigurations related to Fortinet products, which are widely used for network security. The stolen credentials are the primary objective, serving as the gateway for attackers to gain unauthorized access to victim environments.
The attribution of FortiBleed to INC and Lynx ransomware groups is a significant development. Both INC and Lynx are known for their ransomware operations, which involve encrypting victim data and demanding payment for its decryption. The connection suggests that these ransomware gangs are either collaborating or that a single entity is responsible for both the credential theft and the subsequent ransomware deployment.
The implication of stolen credentials being used for "follow-on intrusions" means that once attackers obtain valid usernames and passwords, they can use this information to log into systems, escalate privileges, and move laterally within a compromised network. This phase is critical for attackers as it allows them to establish a persistent presence and identify high-value targets before deploying their ransomware payload.
The financially motivated nature of FortiBleed underscores the economic drivers behind these cyberattacks. The ultimate goal is to extort money from victims, either through ransomware payments or potentially by selling the stolen credentials on the dark web. The campaign represents a multi-stage attack strategy designed to maximize the chances of a successful financial outcome for the attackers.
Security researchers have observed that the threat actors involved in FortiBleed are actively seeking to exploit these stolen credentials. This indicates a proactive and organized approach to cybercrime, where the credential theft is not an end in itself but a crucial step in a larger operation. The efficiency of this approach relies on the assumption that many organizations reuse credentials or have weak password policies, making the stolen information highly valuable.
While specific technical details about the vulnerabilities exploited by FortiBleed are not provided, the campaign's name suggests a potential focus on Fortinet's FortiGate firewalls or related products. These devices often sit at the perimeter of networks and manage user access, making them attractive targets for credential harvesting.
Organizations using Fortinet products, or any network security solutions, are advised to review their security configurations and user authentication practices. This includes implementing strong, unique passwords, enabling multi-factor authentication wherever possible, and regularly monitoring network logs for suspicious login attempts or unusual activity. Promptly patching all security devices and software is also a fundamental best practice to mitigate the risk of exploitation.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed