Infostealers FortiBleed Campaign: AI-Driven Exploitation of Fortinet Firewalls
Article Content
- •FortiBleed compromised 75,000 Fortinet firewalls, affecting 21,632 domains.
- •Attackers utilized a 36-GPU cluster rented from Vast.ai for password cracking.
- •AI tools were employed for managing operations and automating penetration testing.
The FortiBleed campaign exposed valid credentials for nearly 75,000 Fortinet FortiGate firewalls across 21,632 domains. Threat actors leveraged commoditized supercomputing resources to execute massive cryptographic attacks, previously the domain of state intelligence agencies. By renting a 36-GPU cluster from Vast.ai, they efficiently cracked passwords from harvested encrypted configuration files. The attackers utilized AI-assisted tools for managing their operations, including code editors and penetration testing frameworks. This incident highlights a significant shift in cybercrime, where financial motivation and advanced technology allow attackers to bypass traditional security measures. The impact is extensive, affecting numerous enterprises relying on Fortinet devices. The campaign underscores the need for enhanced security protocols to defend against such sophisticated threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track SantaAd, DoublePulsar and Comcast in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…