FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

2026-06-24T01:24:09Z1f91f46a525fa9763a331f53d3ecf75f796c467f6311a4ffd99e2ded90d29756
AI-agent-securityAI-privacyAutoJackCISACVE-2026-4020CastleStealerDifyTapFortiBleedFortiGateGentleKiller','RaaS','EDR-evasion','GitHub-actions','pwn-requestGravitySMTPManageEngine-RMMOXLOADERSecureROMShapedPluginSquidSquidbleedWhatsApp-malspamWindows-RATWordPresscredential-harvestingmalicious-npmsupply-chainunpatchable-exploitusbliter8

What happened

A cluster of high-impact cyber incidents and security updates: a large-scale credential-harvesting campaign dubbed “FortiBleed” (Russian-speaking IAB) has targeted hundreds of thousands of internet-exposed FortiGate appliances and amassed millions of credentials, prompting CISA warnings and active exploitation. Multiple supply-chain and distribution attacks were reported — backdoored ShapedPlugin WordPress Pro releases, malicious npm packages delivering a Windows RAT, and a new OXLOADER/Google‑Ads campaign dropping CastleStealer. Notable vulnerabilities and exploit disclosures include Squidble

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
1f91f46a525fa9763a331f53d3ecf75f796c467f6311a4ffd99e2ded90d29756
Enrichment time
2026-06-24T01:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation · Baitaphish