FortiBleed Credential Theft Connected to INC and Lynx Ransomware
2026-07-02T20:51:42Z•98fb2deb9582c4926ba0c14a899220a06edc238df17df509761c2a26fa92dda9
INC RansomJADEPUFFERLynx ransomwareagentic ransomwarebrowser extensionbrowser token theftcredential theftcriminal-ipcrypto wallet theftddos protectionevilTokensfake interpol emailsfortibleedfortinetgoogle notes extensionlangflowlink11llm agentmysql compromisenacosnextcloud zero-dayopenctiproton drive phishingransomware backup strategiessoc visibility
What happened
Multiple active campaigns and novel threat vectors reported: “FortiBleed” credential-theft activity now linked to INC and Lynx ransomware actors, with a Nextcloud zero-day under investigation; Sysdig documents JADEPUFFER, an agentic ransomware operation that abused a Langflow flaw to steal credentials, reach production MySQL, and destroy Nacos configuration data; a malicious “Google Notes” browser extension (Chrome/Brave/Edge) that swaps copied crypto wallet addresses; phishing emails impersonating Interpol using Proton Drive links to deliver ransomware to small businesses; and EvilTokens, a浏览
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 98fb2deb9582c4926ba0c14a899220a06edc238df17df509761c2a26fa92dda9
- Enrichment time
- 2026-07-02T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.