LIVE · cybersecurity feed
Live wire
ransomware

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An operator tied to Forti

zeroday.news · 30d ago

A financially motivated cyber campaign dubbed "FortiBleed" has been linked to the INC and Lynx ransomware operations, suggesting that the credentials stolen through this activity were intended for subsequent network intrusions. This discovery highlights a coordinated effort where the initial compromise is leveraged to facilitate further malicious activities.

The FortiBleed campaign specifically targets the theft of user credentials. While the exact mechanisms of credential acquisition are not detailed, the campaign's name implies a focus on exploiting vulnerabilities or misconfigurations related to Fortinet products, which are widely used for network security. The stolen credentials are the primary objective, serving as the gateway for attackers to gain unauthorized access to victim environments.

The attribution of FortiBleed to INC and Lynx ransomware groups is a significant development. Both INC and Lynx are known for their ransomware operations, which involve encrypting victim data and demanding payment for its decryption. The connection suggests that these ransomware gangs are either collaborating or that a single entity is responsible for both the credential theft and the subsequent ransomware deployment.

The implication of stolen credentials being used for "follow-on intrusions" means that once attackers obtain valid usernames and passwords, they can use this information to log into systems, escalate privileges, and move laterally within a compromised network. This phase is critical for attackers as it allows them to establish a persistent presence and identify high-value targets before deploying their ransomware payload.

The financially motivated nature of FortiBleed underscores the economic drivers behind these cyberattacks. The ultimate goal is to extort money from victims, either through ransomware payments or potentially by selling the stolen credentials on the dark web. The campaign represents a multi-stage attack strategy designed to maximize the chances of a successful financial outcome for the attackers.

Security researchers have observed that the threat actors involved in FortiBleed are actively seeking to exploit these stolen credentials. This indicates a proactive and organized approach to cybercrime, where the credential theft is not an end in itself but a crucial step in a larger operation. The efficiency of this approach relies on the assumption that many organizations reuse credentials or have weak password policies, making the stolen information highly valuable.

While specific technical details about the vulnerabilities exploited by FortiBleed are not provided, the campaign's name suggests a potential focus on Fortinet's FortiGate firewalls or related products. These devices often sit at the perimeter of networks and manage user access, making them attractive targets for credential harvesting.

Organizations using Fortinet products, or any network security solutions, are advised to review their security configurations and user authentication practices. This includes implementing strong, unique passwords, enabling multi-factor authentication wherever possible, and regularly monitoring network logs for suspicious login attempts or unusual activity. Promptly patching all security devices and software is also a fundamental best practice to mitigate the risk of exploitation.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.