news.mlab.sh
Back to the feed
threat-intel

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

High
Image: The Hacker News
Summary

A Russian-speaking threat actor, dubbed FortiBleed, is conducting a large-scale credential harvesting operation targeting over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, utilizes a Golang-based tool, FortigateSniffer, to passively capture authentication traffic and then cracks the resulting credentials for use in attacks against Active Directory domains and other services. The operation has resulted in the identification of over 110 million credentials, primarily targeting SMBs in the United States and India, and involves a multi-vendor approach including Synology NAS and Sophos firewalls.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.