FortiBleed Becomes a Credential-Resale Problem

FortiBleed has moved from exposure to reuse. The real break is a confirmed set of more than 86,000 working Fortinet logins that can be reused, sold, or pointed at specific targets, so patching the original flaws does not undo access already harvested. Fortinet says the campaign is driven by reused credentials and brute-force attacks against weak password hygiene and no MFA, not a new Fortinet bug. The credentials cover FortiGate and SSL VPN environments in 194 countries, and the leak is now being formatted like eCrime inventory instead of a one-off dump. That changes the threat from a leak around a vendor to direct entry into any network that still trusts a reused FortiGate or VPN password. The forward risk is focused intrusion, session abuse, and admin changes through working credentials that remain valid after the original issue is closed.

Part of the PlainSec briefing for 2026-06-23

Sources