430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link

2026-07-02T14:51:45Zf83726cc723e5f1ec81c99268b8c1dc0c6e73255fe9f20e492bc60727322b522
AI-agentsAdobeAzure CLIBlueHammerCISACampaign ClassicColdFusionFortiBleedFortiGateGuardFallINC RansomLSHIYLynxOracle E-Business SuiteRustDuckScattered SpiderSimpleHelpXSS.isactive-exploitationbotnetcredential-harvestcybercrime-forumpassword-sprayransomware

What happened

Multiple high-impact, actively exploited incidents and critical vulnerabilities were reported: SOCRadar links the ‘FortiBleed’ campaign to credential harvesting from ~430,000 FortiGate devices and at least a dozen ransomware incidents (INC Ransom, Lynx); Oracle E-Business Suite vulnerability CVE-2026-46817 is under active exploitation with ~950 internet-exposed instances; CISA confirms BlueHammer (CVE-2026-33825) is being used in ransomware attacks to escalate privileges in Microsoft Defender; SimpleHelp authentication-bypass CVE-2026-48558 (CVSS 10.0) was added to CISA’s KEV; Adobe released 0

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f83726cc723e5f1ec81c99268b8c1dc0c6e73255fe9f20e492bc60727322b522
Enrichment time
2026-07-02T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.