FortiBleed Credential Theft Connected to INC and Lynx Ransomware

2026-07-02T20:51:42Z98fb2deb9582c4926ba0c14a899220a06edc238df17df509761c2a26fa92dda9
INC RansomJADEPUFFERLynx ransomwareagentic ransomwarebrowser extensionbrowser token theftcredential theftcriminal-ipcrypto wallet theftddos protectionevilTokensfake interpol emailsfortibleedfortinetgoogle notes extensionlangflowlink11llm agentmysql compromisenacosnextcloud zero-dayopenctiproton drive phishingransomware backup strategiessoc visibility

What happened

Multiple active campaigns and novel threat vectors reported: “FortiBleed” credential-theft activity now linked to INC and Lynx ransomware actors, with a Nextcloud zero-day under investigation; Sysdig documents JADEPUFFER, an agentic ransomware operation that abused a Langflow flaw to steal credentials, reach production MySQL, and destroy Nacos configuration data; a malicious “Google Notes” browser extension (Chrome/Brave/Edge) that swaps copied crypto wallet addresses; phishing emails impersonating Interpol using Proton Drive links to deliver ransomware to small businesses; and EvilTokens, a浏览

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
98fb2deb9582c4926ba0c14a899220a06edc238df17df509761c2a26fa92dda9
Enrichment time
2026-07-02T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.