Network & InfrastructureBleeping Computer
8.5 — CRITICAL
FortiBleed campaign used custom FortiGate sniffer to steal credentials
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
The FortiBleed campaign used custom FortiGate sniffers to steal credentials from compromised firewalls, targeting over 430,000 FortiGate devices worldwide since at least February 2026.
⚙️Technical Details
Affected Systems
Fortinet FortiGate devices
Attack Vectors
Credential stuffing and brute-force attacksAbuse of FortiOS's built-in diagnose sniffer packet functionality
💥Impact Assessment
Severity: High
Who Is at Risk
Organizations utilizing FortiGate devices
🛡️Recommended Actions
1Review the list of targeted IP addresses and investigate whether any systems were compromised
2Enable authentication traffic monitoring on FortiGate devices
3Implement additional security measures to prevent credential stuffing and brute-force attacks
📦Affected Products
Fortinet FortiGate devices
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
