ransomware
FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs
High
Summary
The FortiBleed operation, initially focused on stealing credentials from thousands of Fortinet FortiGate firewalls, has expanded to involve ransomware-as-a-service (RaaS) gangs Inc Ransom and Lynx. SOCRadar researchers discovered a single operator coordinating with both groups, leveraging stolen credentials to deploy ransomware and potentially exploit a Nextcloud zero-day vulnerability. This development significantly elevates the risk for FortiGate users, moving beyond simple credential theft to active ransomware attacks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
