Minacce · 97 giorni fa
Il punto non è solo la compromissione del firewall. Una volta dentro un FortiGate, l'attaccante lo trasforma in un nodo che ascolta il traffico di autenticazione, estrae password e hash, poi li monetizza fuori dal dispositivo; la correzione del bordo non cancella l'accesso già raccolto. Con FortiGate gestiti da MSP e provider IT, l'effetto si estende anche ai clienti a valle.
SOCRadar stima che FortiBleed abbia preso di mira oltre 430.000 FortiGate in tutto il mondo e abbia prodotto più di 110 milioni di credenziali; i target attivi sono oltre 19.000. Il report lega la campagna a un initial access broker a movente finanziario e a un flusso automatizzato con FortigateSniffer, cracking su GPU affittate e orchestrazione via Telegram, con uso successivo delle credenziali contro Active Directory e altri servizi.
Il cambio di scala conta: non è più solo un singolo sniffer su Fortinet, ma una pipeline multi-vendor che industrializza il furto di accesso. Per chi opera firewall per conto terzi, la compromissione dell'appliance può diventare subito un problema di identità e di accesso downstream, non un incidente confinato al perimetro.
6 fonti che coprono questa storia
Risky Bulletin: FortiBleed hacks involved a lot of traffic sniffing
The FortiBleed hacks are worse than a credentials leak, a new White House executive order sets out a hard 2031 post quantum cryptography d [Read More
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
FortiBleed targeted 430,000 FortiGate firewalls with sniffers and brute-force pipelines that identified over 110 million credentials.
What the Fortibleed campaign means for organizations running FortiGate firewalls - Help Net Security
Analysts have pieced together the full attack chain from the FortiBleed leak, revealing a sophisticated, highly automated pipeline.
FortiBleed Attackers Turn Firewalls Into Credentials Stealers
The threat actors used a Golang-based sniffer to target 430,000 FortiGate firewalls and identify 110 million credentials in the ongoing global campaign.
Russian Initial Access Broker Behind FortiBleed Campaign
Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.
FortiBleed campaign used custom FortiGate sniffer to steal credentials
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials.
Part of the PlainSec briefing for 2026-06-25