Skip to content
Nightspire Targets DiamondLease and Tuboaços da Amazônia with FortiBleed Exploits

Nightspire Targets DiamondLease and Tuboaços da Amazônia with FortiBleed Exploits

First seen 11 Sep 2026, 19:43 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 12, 2026 at 04:12 UTC
  • Nightspire has targeted two companies, DiamondLease and Tuboaços da Amazônia, using the FortiBleed vulnerability.
  • Both companies' FortiOS SSL-VPN credentials were exposed, indicating a significant security breach.
  • CVE-2022-40684 has been actively exploited since its addition to the CISA KEV list in October 2022.

On September 11, 2026, ransomware group Nightspire announced two new victims: DiamondLease and Tuboaços da Amazônia Ltda. Both companies had their FortiOS SSL-VPN credentials exposed due to the FortiBleed vulnerability (CVE-2022-40684). This vulnerability was published on October 18, 2022, and was added to the CISA KEV list for active exploitation on October 11, 2022. The DNS records for both victims were publicly indexed, revealing their use of Microsoft 365 services. The attack highlights the ongoing threat posed by ransomware groups exploiting known vulnerabilities. The current status indicates that both companies are dealing with the aftermath of the breach. No specific details on the extent of the data compromised have been disclosed yet.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2022-10-09
First public PoC for CVE-2022-40684
Proof-of-concept code for the FortiBleed vulnerability was released publicly, raising security concerns.
Ransomware.Live
2022-10-11
CVE-2022-40684 added to CISA KEV
CISA listed the FortiBleed vulnerability for active exploitation, alerting organizations to the threat.
Ransomware.Live
2022-10-18
CVE-2022-40684 published
The vulnerability affecting FortiOS SSL-VPN was officially published, detailing its impact.
Ransomware.Live
2026-09-11
Nightspire announces new victims
Ransomware group Nightspire publicly claimed DiamondLease and Tuboaços da Amazônia as their latest victims.
Ransomware.Live

More articles in this cluster (3)

Following this threat?

Track DiamondLease and CVE-2022-40684 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed