Ransomware.Live Nightspire Targets DiamondLease and Tuboaços da Amazônia with FortiBleed Exploits
Article Content
- •Nightspire has targeted two companies, DiamondLease and Tuboaços da Amazônia, using the FortiBleed vulnerability.
- •Both companies' FortiOS SSL-VPN credentials were exposed, indicating a significant security breach.
- •CVE-2022-40684 has been actively exploited since its addition to the CISA KEV list in October 2022.
On September 11, 2026, ransomware group Nightspire announced two new victims: DiamondLease and Tuboaços da Amazônia Ltda. Both companies had their FortiOS SSL-VPN credentials exposed due to the FortiBleed vulnerability (CVE-2022-40684). This vulnerability was published on October 18, 2022, and was added to the CISA KEV list for active exploitation on October 11, 2022. The DNS records for both victims were publicly indexed, revealing their use of Microsoft 365 services. The attack highlights the ongoing threat posed by ransomware groups exploiting known vulnerabilities. The current status indicates that both companies are dealing with the aftermath of the breach. No specific details on the extent of the data compromised have been disclosed yet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track DiamondLease and CVE-2022-40684 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…