news.mlab.sh
Back to the feed
threat-intel

Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

High
Image: Palo Alto Unit 42
Summary

A significant campaign, dubbed “TheHatman” and “FortiBleed,” is targeting organizations with leaked credentials, primarily leveraging password spraying against Fortinet and Sophos devices. TheHatman, an actor offering stolen credentials, has been active since August 1st, 2026, and has claimed to exfiltrate sensitive data from multiple high-profile enterprises. The FortiBleed campaign involved a large-scale password spraying and credential theft campaign against Fortinet devices, with an initial breach disclosed in June 2026. Unit 42 recommends proactive measures like auditing remote access logs, implementing hardening guidelines (including MFA, ZTNA, and credential rotation), and leveraging threat intelligence sharing through the Cyber Threat Alliance. Palo Alto Networks’ Cortex Cloud Identity Security and Idira Identity Threat Protection are key products for mitigating these attacks.

Read the full article at Palo Alto Unit 42

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.