Home / Jun 25, 2026 / Story
0
#6 SecurityWeek general June 23, 2026 at 10:30 UTC

Russian Initial Access Broker Behind FortiBleed Campaign

By Ionut Arghire

AI Summary

A Russian initial access broker behind the 'FortiBleed' campaign deployed a custom Golang-based sniffer targeting 430,000 FortiGate firewalls, capturing over 110 million credentials since at least February 2026. The campaign repurposes compromised FortiGate devices as credential-harvesting infrastructure, posing an outsized risk to organizations that have not fully remediated known FortiOS vulnerabilities.

Relevance score: 82.0/100

# More from June 25