FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
2026-06-24T07:24:17Z•70bcdfe3b0bf8d2d67d494e2f66f51ceb56a146eb9e2a19706a92e73e44fbb30
AI-agent-securityApple-A12-A13AutoJackCISACastleStealerDifyTapFortiBleedFortiGateFortinetGitHub-actionsOXLOADERSecureROMShapedPluginSquid-proxySquidbleedWindows-RATWordPressactions/checkoutcredential-harvestingmalicious-npmmulti-tenant-data-leakpwn-request-attack-patterns','OpenAI-Daybreak','GPT-5.5-Cyber','supply-chainunpatchable-exploitusbliter8
What happened
A large, ongoing credential-harvesting campaign dubbed “FortiBleed” (Russian-speaking IAB) has targeted FortiGate appliances worldwide—compromising hundreds of thousands of devices and prompting CISA warnings. The feed also reports multiple high-impact supply-chain and large-scale threats: backdoored ShapedPlugin WordPress Pro releases, malicious npm packages delivering a Windows RAT, and a new OXLOADER loader distributing CastleStealer via malicious Google Ads. Other notable issues include a disclosed Squid proxy data-leak (Squidbleed), an unpatchable SecureROM exploit for Apple A12/A13 (usbl
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 70bcdfe3b0bf8d2d67d494e2f66f51ceb56a146eb9e2a19706a92e73e44fbb30
- Enrichment time
- 2026-06-24T07:24:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.