FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
2026-06-24T01:24:09Z•1f91f46a525fa9763a331f53d3ecf75f796c467f6311a4ffd99e2ded90d29756
AI-agent-securityAI-privacyAutoJackCISACVE-2026-4020CastleStealerDifyTapFortiBleedFortiGateGentleKiller','RaaS','EDR-evasion','GitHub-actions','pwn-requestGravitySMTPManageEngine-RMMOXLOADERSecureROMShapedPluginSquidSquidbleedWhatsApp-malspamWindows-RATWordPresscredential-harvestingmalicious-npmsupply-chainunpatchable-exploitusbliter8
What happened
A cluster of high-impact cyber incidents and security updates: a large-scale credential-harvesting campaign dubbed “FortiBleed” (Russian-speaking IAB) has targeted hundreds of thousands of internet-exposed FortiGate appliances and amassed millions of credentials, prompting CISA warnings and active exploitation. Multiple supply-chain and distribution attacks were reported — backdoored ShapedPlugin WordPress Pro releases, malicious npm packages delivering a Windows RAT, and a new OXLOADER/Google‑Ads campaign dropping CastleStealer. Notable vulnerabilities and exploit disclosures include Squidble
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 1f91f46a525fa9763a331f53d3ecf75f796c467f6311a4ffd99e2ded90d29756
- Enrichment time
- 2026-06-24T01:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.