FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries

2026-06-17T20:51:42Z0b46ef03e350d76a299ad43c1580259258d07f1dc38bf686cd5394564c4a0240
ad-fraudai-riskamos-stealerandroid-trojanapi-key-theftbanking-trojanchrome-extensionscredential-stuffingcredentials-theftexposed-firewallsfortibleedfortinetjetbrainsmacos-keychainmalicious-pluginsmdrphishingrokarollasecurity-productsspycloudsupply-chainthreat-intelligence

What happened

Multiple high-impact incidents reported: "FortiBleed" credential-stuffing attacks used stolen/tested credentials to access exposed Fortinet firewalls in ~194 countries, putting major organizations and public agencies at risk. Other notable threats include 15 malicious JetBrains plugins stealing developer API keys (DeepSeek, OpenAI, etc.), Amos Stealer targeting macOS Keychain and browser credentials, and the Rokarolla Android trojan targeting 217 crypto and banking apps. Additional coverage: Chrome Live Wallpaper extensions conducting ad-tracking and fake-click inflation, a SpyCloud report on

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
0b46ef03e350d76a299ad43c1580259258d07f1dc38bf686cd5394564c4a0240
Enrichment time
2026-06-17T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries · Baitaphish