What the Fortibleed campaign means for organizations running FortiGate firewalls
2026-06-23T14:51:49Z•ae4d877ced6c4b83f5432b8bdc8ca6068eb772ff2859742ce4e7f4bb605b0fe1
CloudSEKFortiBleedFortiGateZenoXattacker-toolscredential-harvestingdata-exposurehigh-impactinvestigationnetwork-compromiseremediation
What happened
A widespread credential-harvesting campaign dubbed “FortiBleed” targeting FortiGate firewalls has exposed thousands of organizations. Researchers at ZenoX and CloudSEK recovered a trove of attacker tools, scripts, and harvested credentials from an exposed server and reconstructed a highly automated attack pipeline that in some cases achieved full domain-level control. Organizations running FortiGate appliances should treat this as urgent—assume possible compromise, prioritize investigation and remediation (credential rotation, forensic log review, apply vendor mitigations/patches, and hunt for
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- ae4d877ced6c4b83f5432b8bdc8ca6068eb772ff2859742ce4e7f4bb605b0fe1
- Enrichment time
- 2026-06-23T14:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.