FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

2026-06-24T07:24:17Z70bcdfe3b0bf8d2d67d494e2f66f51ceb56a146eb9e2a19706a92e73e44fbb30
AI-agent-securityApple-A12-A13AutoJackCISACastleStealerDifyTapFortiBleedFortiGateFortinetGitHub-actionsOXLOADERSecureROMShapedPluginSquid-proxySquidbleedWindows-RATWordPressactions/checkoutcredential-harvestingmalicious-npmmulti-tenant-data-leakpwn-request-attack-patterns','OpenAI-Daybreak','GPT-5.5-Cyber','supply-chainunpatchable-exploitusbliter8

What happened

A large, ongoing credential-harvesting campaign dubbed “FortiBleed” (Russian-speaking IAB) has targeted FortiGate appliances worldwide—compromising hundreds of thousands of devices and prompting CISA warnings. The feed also reports multiple high-impact supply-chain and large-scale threats: backdoored ShapedPlugin WordPress Pro releases, malicious npm packages delivering a Windows RAT, and a new OXLOADER loader distributing CastleStealer via malicious Google Ads. Other notable issues include a disclosed Squid proxy data-leak (Squidbleed), an unpatchable SecureROM exploit for Apple A12/A13 (usbl

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
70bcdfe3b0bf8d2d67d494e2f66f51ceb56a146eb9e2a19706a92e73e44fbb30
Enrichment time
2026-06-24T07:24:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation · Baitaphish