/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A newly discovered data leak has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs across 194 countries

A newly discovered data leak dubbed “FortiBleed” has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials …

BleepingComputer Lawrence Abrams

Context & Ripple Effects

This is the latest in a recurring Fortinet access-security story: related coverage previously documented a large VPN-credential leak, actively exploited flaws in Fortinet management and authentication products, and a substantial population of exposed SSL VPN interfaces that remained unpatched after a major FortiOS fix.

The new dataset broadens the operational concern from a product vulnerability to potentially reusable access credentials spanning a large, internationally distributed set of firewall endpoints. For Fortinet customers, credential hygiene and internet-facing VPN exposure are again central risks alongside patching.

First-order effects

  • Organizations whose Fortinet/FortiGate VPN endpoints appear in the leak need to treat the credentials as potentially compromised, rotate affected VPN accounts, and review authentication and access logs for misuse.
  • Fortinet faces renewed customer-support and trust pressure around securing remote-access deployments, even though the reported exposure concerns credentials rather than a newly stated product flaw.

Second-order effects

  • Security teams and managed service providers will likely prioritize inventorying internet-facing Fortinet VPNs, enforcing stronger authentication controls, and accelerating remediation of known exposed or unpatched instances.
  • Attackers can use leaked credentials as an alternative route to exploiting appliance vulnerabilities, increasing the value of monitoring for valid-account activity rather than focusing only on exploit signatures.

Third-order effects

  • If repeated credential disclosures and exploitation of edge-security products persist, enterprise perimeter security will increasingly depend on continuous credential rotation, multifactor authentication, and exposure management—not episodic appliance patch cycles alone.
  • The pattern raises the strategic cost for network-security vendors: customers will judge product security not only by vulnerability response but by how effectively deployments resist credential-based compromise and remain manageable at scale.

The trend: FortiBleed is another data point in the convergence of exposed remote-access infrastructure, leaked credentials, and known edge-device vulnerabilities into a persistent enterprise access-risk problem.

Discussion

  • @thehackersnews @thehackersnews on x
    UPDATE 🠖 FortiBleed looks bigger than first reported. Update: Hudson Rock says FortiBleed targeted 73,932 Fortinet firewall URLs across 194 countries, affecting 21,632 domains. The bigger risk: exposed FortiGate SSL VPNs may be used as listening posts to capture more [image]
  • @dailydarkweb @dailydarkweb on x
    🌍 Global - FortiBleed Exposes 30,791 Compromised Fortinet Devices SOCRadar researchers uncovered an active campaign targeting Fortinet firewalls and VPN gateways worldwide. Key findings: * 30,791 compromised Fortinet devices identified * 21,108 unique IP addresses affected * [ima…
  • @socradar @socradar on x
    🚨 Meet #FortiBleed. If you are running Fortinet, it is time to check your logs. Our Threat Research team just uncovered a massive, active campaign with 30,000+ compromised Fortinet firewall credentials across 194 countries. The US is target #2. Banks, telecoms, and gov
  • @intcyberdigest @intcyberdigest on x
    ‼️🚨 BREAKING: 320,000 Fortinet firewall devices have been targeted in a campaign that has been dubbed ‘FortiBleed’. Attackers were able to confirm 75,000 working credentials against the admin and SSL VPN interfaces. The victims include really big names like Samsung, Oracle, [imag…
  • Volodymyr “Bob” Diachenko Volodymyr “Bob” Diachenko on linkedin
    Executive summary based on my investigation report:  — This is a Russian-speaking multi-operator group conducting large-scale credential harvesting …
  • Volodymyr “Bob” Diachenko Volodymyr “Bob” Diachenko on linkedin
    Massive Fortinet/FortiGate bruteforce/active exploitation campaign uncovered in action.  Thousands of top vendors instances are listed in the files like this (see screenshot). …