IntelliOS panda
FortiBleed Fortinet Credential Exposure
FortiBleed is best framed as a reported Fortinet/FortiGate credential-exposure dataset tied to roughly 73,932 firewall or SSL VPN URLs worldwide, not as a clean count of unique physical devices. 22-Jun-2026 · Added SOCRadar and BleepingComputer now describe FortiBleed as an active credential-harvesting operation using a custom FortigateSniffer tool and broader infrastructure, not only a previously published static leak list. 23-Jun-2026 · Revised The sniffer activity should be scoped as a post-compromise harvesting and scale mechanism: once attackers have FortiGate administrative or SSH-level access, they can abuse legitimate diagnostic packet capture to collect more credentials and feed additional cracking, replay, or access attempts. 24-Jun-2026 · Added Arctic Wolf's reverse-engineering update adds a recovered-tooling view: CyberStrike Harvester, FortiGate Sniffer panel references, AD/SMB tooling, credential cleaners, Hashcat/Hashtopolis workflows, and post-authentication capture processing. Use these as hunt pivots, not public raw IOCs or victim evidence. Fortinet says the activity is not a new Fortinet vulnerability and is not related to a recent incident or advisory; CISA nevertheless urges hardening because exposed credentials can still create immediate access risk. The immediate risk is unauthorized edge access: records reportedly include usernames, email addresses, and plaintext passwords in many cases, creating a direct path to VPN or firewall administration if credentials are still valid. 29-Jun-2026 · Revised Current SOCRadar reporting expands the scoping lens to 59.3M scanned hosts, 430,000+ targeted FortiGate firewalls, 90,000+ IP addresses, 750,000+ credentials, 105M+ records, 80,553 unique devices, 23,406 organizational domains, 260+ operation servers, and 659+ harvest cycles; keep those figures distinct from the earlier 73,932 URL dataset. 20-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 20 update date, says new compromised devices are being added, and retains the same 437K+/90K+/750K+/105M+ headline metrics. 30-Jun-2026 · Revised SOCRadar states it attributes FortiBleed to Lynx / INC. 22-Jul-2026 · Added Newly retained; published >24h before this run: SOCRadar's public Volume II landing page now supports high-level operator/hierarchy, workflow, AI-assisted-operation, targeting, ATT&CK, and IoC-availability framing. Treat this as SOCRadar attribution and operation-structure context, not proof that every listed exposure, credential use, or downstream intrusion is attributable to that grouping. 2-Jul-2026 · Added SOCRadar now adds a ransomware-impact layer: it says FortiBleed infrastructure is directly connected to INC Ransom and Lynx ransomware operations, with admin-level access confirmed on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments from FortiBleed-derived access. 22-Jul-2026 · Added Newly retained; published >24h before this run: SOCRadar's public Volume II landing page now supports the higher-level operator, internal-workflow, AI-assisted-operation, targeting, ATT&CK, and IoC-availability framing that was previously caveated as pending a public whitepaper. Treat these as SOCRadar-reported findings, not a public victim list or proof for every exposed organization. 6-Jul-2026 · Added Freshly reported (<24h): UK press reporting adds a public-sector exposure cluster, saying FortiBleed-linked stolen-login activity affected UK Foreign Office and local-government account examples and citing NCSC Fortinet brute-force alerting. 7-Jul-2026 · Added Newly retained; published >24h before this run: NCSC's official June 18 alert directly supports UK-focused checker validation, IoC review, isolation/factory-reset escalation, shared-credential scoping, management-interface hardening, MFA, and PBKDF2 enforcement. Treat media reporting as public-sector scoping context, not a confirmed raw victim list or proof of successful compromise for every named organization. 26-Aug-2026 · Added Newly retained; published >24h before this run: Canada's Cyber Centre official June 18 alert adds Canadian government guidance for Fortinet account inventory, suspicious-account removal, management-interface restriction, session termination, password resets, MFA, firmware review, and reporting matching activity through Cyber Centre channels. Treat it as official response guidance, not as a new victim list or confirmed compromise count. 16-Aug-2026 · Added Newly retained; published >24h before this run: BGD e-GOV CIRT's July 7 advisory identifies 153 unique Bangladesh IP addresses associated with the FortiBleed tag. Treat this as regional exposure-scoping and investigation guidance, not a confirmed breach count or public victim list. 27-Jul-2026 · Added Newly retained; published >24h before this run: CHT Security's first-party statement says its FortiBleed mention reflected FortiSupport Partner account use during customer product-registration/support workflows, and that CHT Security found no internal intrusion, data leak, or security impact. Treat this as deconfliction evidence for named-list handling, not as a public victim compromise confirmation. 7-Aug-2026 · Added Newly retained; published >24h before this run: CybelAngel's June 25 flash-report summary adds a concrete persistence-review pivot: Fortinet-service-like administrator account names such as forticloud-sync, forticloud-tech, support_fortinet, fgtsecure, fgtsec, Technical_support, fortinetadmin, adminin, and tech-fortinet. Use these as local hunt terms, not proof of compromise by themselves. 13-Aug-2026 · Added Newly retained; published >24h before this run: Roche's June 30 first-party advisory says two Roche-associated FortiGate devices appeared in the FortiBleed dataset, but Roche found no evidence of impact to Roche customer Laboratory Networks. Treat this as deconfliction and customer-impact boundary evidence, not proof of broader Roche, customer, or device compromise. 23-Jun-2026 · Added SpyCloud Labs independently adds a multi-server access-broker infrastructure view, including broader non-Fortinet scanning and AI-assisted operator tooling; use it to widen hunting without publishing raw infrastructure, victim, or credential data. 26-Jun-2026 · Added Newly retained Recorded Future/Insikt reporting adds seller-credibility deconfliction: it assesses SantaAd as likely credible while describing a separate low-credibility copycat or re-extortion effort. 5-Jul-2026 · Clarified Also use it as behavior-level workflow/infrastructure corroboration for private scoping, not to publish raw artifacts, acquisition paths, infrastructure, or victim details. 23-Jun-2026 · Added Sophos now provides an official adjacent-device boundary: the same threat actors reportedly targeted internet-exposed Sophos Firewall appliances through user-level credential brute-forcing or stuffing, but Sophos had not observed Sophos Firewall compromise or exploitation of a Sophos Firewall vulnerability in reviewed telemetry. Organizations using FortiGate SSL VPN or internet-facing Fortinet administrative interfaces should treat this as an identity, remote-access, and configuration-review issue, not only a vulnerability-management ticket. Scoping should start with owned domains, trusted FortiBleed checkers, public Fortinet/FortiGate URLs, Fortinet account exports, active SSL VPN/admin sessions, authentication logs, admin-change logs, MFA status, suspicious-account review, and password-rotation history. No retained public source provides a reliable count of stolen Fortinet passwords successfully used against victims, or a reliable count of firewalls where attackers changed passwords, settings, or administrator accounts; those outcomes require local Fortinet telemetry. A positive dataset or lookup hit should trigger urgent validation and containment, but dataset inclusion alone does not prove successful intrusion, data theft, or that every credential still works.
Research Framing
User Topic
FortiBleed Leaks Exposes Fortinet Credentials for 73,000 VPN Devices
Field: User Topic Value: FortiBleed Leaks Exposes Fortinet Credentials for 73,000 VPN Devices
Decision Question
Should an organization treat the FortiBleed reporting as evidence requiring immediate credential rotation, exposed-device validation, and incident scoping even though Fortinet states that it is not a new Fortinet vulnerability?
Field: Decision Question Value: Should an organization treat the FortiBleed reporting as evidence requiring immediate credential rotation, exposed-device validation, and incident scoping even though Fortinet states that it is not a new Fortinet vulnerability?
Interpreted Questions
What is actually happening around FortiBleed? Which sources make the claim credible, current, or caveated? Who is exposed, why does it matter, and what should defenders do first?
Field: Interpreted Questions Value: What is actually happening around FortiBleed? Which sources make the claim credible, current, or caveated? Who is exposed, why does it matter, and what should defenders do first?
Initial Observations
Public reporting and newly retained primary or near-primary sources support a cautious assessment that FortiBleed refers to both a reported Fortinet/FortiGate credential-exposure dataset tied to approximately 73,932 firewall or SSL VPN URLs and 22-Jun-2026 · Added a newer SOCRadar-described active operation involving FortigateSniffer, operation servers, harvest cycles, and broader credential-collection infrastructure. 23-Jun-2026 · Added SpyCloud adds broader IAB infrastructure context. Fortinet states this is not a new Fortinet vulnerability, while CISA urges hardening because exposed credentials remain operationally dangerous.
Field: Initial Observations Value: Public reporting and newly retained primary or near-primary sources support a cautious assessment that FortiBleed refers to both a reported Fortinet/FortiGate credential-exposure dataset tied to approximately 73,932 firewall or SSL VPN URLs and 22-Jun-2026 · Added a newer SOCRadar-described active operation involving FortigateSniffer, operation servers, harvest cycles, and broader credential-collection infrastructure. 23-Jun-2026 · Added SpyCloud adds broader IAB infrastructure context. Fortinet states this is not a new Fortinet vulnerability, while CISA urges hardening because exposed credentials remain operationally dangerous.[4] [5] [6] [9] [10] [13] [14] [16] [25] [26] [27] [29]
Fact / Analysis / Unknown Boundaries
The retained sources support a credential-exposure and access-validation problem. They do not prove that every listed URL is a distinct device, that every credential remains valid, that every associated organization was compromised, or that the reporting establishes a new Fortinet vulnerability.
Field: Fact / Analysis / Unknown Boundaries Value: The retained sources support a credential-exposure and access-validation problem. They do not prove that every listed URL is a distinct device, that every credential remains valid, that every associated organization was compromised, or that the reporting establishes a new Fortinet vulnerability.
Source Coverage
Field: Source Coverage
Tier 0 - Most Trusted
48
Field: Tier 0 - Most Trusted Value: 48 2 2 46
Tier 1 - Authoritative
59
Field: Tier 1 - Authoritative Value: 59 5 5 54
Tier 2 - High-Value Research
228
Field: Tier 2 - High-Value Research Value: 228 3 3 225
Tier 3 - Corroborating News
187
Field: Tier 3 - Corroborating News Value: 187 6 6 181
Tier 4 - Community Signal
53
Field: Tier 4 - Community Signal Value: 53 0 0 53
Tier 5 - Custom Source
0
Field: Tier 5 - Custom Source Value: 0 0 0 0
Tier 6 - Custom Integrations with API/Keys
1
Field: Tier 6 - Custom Integrations with API/Keys Value: 1 0 0 1
Tier 7 - Inner Discovery
0
Field: Tier 7 - Inner Discovery Value: 0 0 0 0
Tier 8 - Expansion Research / AI Agent Delta
18
Field: Tier 8 - Expansion Research / AI Agent Delta Value: 18 18 18 0
Total
592
Field: Total Value: 592 34 34 558
FortiBleed Exposure Snapshot
Default or admin-like names such as admi* and admi***
SOCRadar's username table shows these two masked admin-like values as the largest exposed username patterns, together representing roughly one-third of listed entries.
Pattern: Default or admin-like names such as admi* and admi*** Reported Signal: SOCRadar's username table shows these two masked admin-like values as the largest exposed username patterns, together representing roughly one-third of listed entries. How To Use It: Prioritize review of default admin, stale admin, shared admin, and reused administrator-style accounts across Fortinet VPN and firewall administration.[12]
Fortinet/FortiGate-themed names such as fgts*****, forti***, and fortig****
SOCRadar reports Fortinet-themed usernames among the most common patterns, including one masked FortiGate-style value near the top of the table.
Pattern: Fortinet/FortiGate-themed names such as fgts*****, forti***, and fortig**** Reported Signal: SOCRadar reports Fortinet-themed usernames among the most common patterns, including one masked FortiGate-style value near the top of the table. How To Use It: Use as an account-inventory and rotation prompt; do not treat masked username patterns as deterministic IOCs or proof of local compromise.[12]
Reported firewall / SSL VPN URLs
73,932
Reported affected domains
~21,632
Reported geographic scope
194 countries
Official vulnerability status
No new CVE
Scoping Funnel
This funnel is the core counsel/client distinction: public exposure is a starting signal, not proof of breach, persistence, exfiltration, or loss.
Immediate Control Posture
Visual order reflects recommended response sequencing, not measured completion or statistical priority.
For fast portfolio, client, policyholder, or owned-asset triage, SOCRadar publishes a free FortiBleed exposure checker that accepts a domain, IP address, or CIDR range and returns whether the submitted asset appears in its FortiBleed dataset. Treat a hit as a scoping trigger, not standalone proof of breach.[27]
AI Agent Delta Snapshot
59.3M
Scanned hosts
430K+
Targeted FortiGate firewalls
90K+
Target IPs
80,553
Unique devices
23,406
Organizational domains
105M+
Records
659+
Harvest cycles
23-Jun-2026 · Added Credential Username Pattern Signal
Topic
FortiBleed is being reported as a large Fortinet/FortiGate credential-exposure or credential-compromise dataset affecting firewall and SSL VPN access paths. The most defensible framing is not 73,000 confirmed VPN devices, but approximately 73,932 Fortinet/FortiGate firewall or SSL VPN URLs associated with organizations worldwide.[4] [5] [6] [9] [10] [16]
The exposure reportedly includes usernames, email addresses, plaintext passwords in many cases, and device-related metadata in some reporting. Organizations using FortiGate SSL VPN or exposing Fortinet administrative interfaces to the internet should treat the reporting as a credential-risk and access-validation problem rather than as a confirmed new Fortinet vulnerability.[13] [14]
22-Jun-2026 · Added The latest delta adds an active-operation layer: SOCRadar describes FortigateSniffer-driven credential harvesting, operation servers, PCAP processing, cracking workflows, and wider targeting metrics. That makes this brief both an exposure-scoping product and an active threat-hunting product.[25] [26] [27]
Persona / Audience Lens
This product is written for executives, IT leaders, security managers, legal/communications stakeholders, and incident-response coordinators who need practical scoping. The central task is determining whether owned domains, Fortinet/FortiGate URLs, SSL VPN endpoints, or internet-facing Fortinet administrative interfaces may be represented in the reported dataset; then prioritizing credential rotation, MFA enforcement, access restriction, and authentication-log review.[3] [5] [6]
BLUF
FortiBleed is best framed as a reported Fortinet/FortiGate credential-exposure dataset tied to roughly 73,932 firewall or SSL VPN URLs worldwide, not as a clean count of unique physical devices.[4] [5] [6] [9] [10] [16]
22-Jun-2026 · Added SOCRadar and BleepingComputer now describe FortiBleed as an active credential-harvesting operation using a custom FortigateSniffer tool and broader infrastructure, not only a previously published static leak list.[25] [26] [27] [28] [35]
23-Jun-2026 · Revised The sniffer activity should be scoped as a post-compromise harvesting and scale mechanism: once attackers have FortiGate administrative or SSH-level access, they can abuse legitimate diagnostic packet capture to collect more credentials and feed additional cracking, replay, or access attempts.[25] [26]
24-Jun-2026 · Added Arctic Wolf's reverse-engineering update adds a recovered-tooling view: CyberStrike Harvester, FortiGate Sniffer panel references, AD/SMB tooling, credential cleaners, Hashcat/Hashtopolis workflows, and post-authentication capture processing. Use these as hunt pivots, not public raw IOCs or victim evidence.[31]
Fortinet says the activity is not a new Fortinet vulnerability and is not related to a recent incident or advisory; CISA nevertheless urges hardening because exposed credentials can still create immediate access risk.[13] [14]
The immediate risk is unauthorized edge access: records reportedly include usernames, email addresses, and plaintext passwords in many cases, creating a direct path to VPN or firewall administration if credentials are still valid.[4] [5] [11] [15]
29-Jun-2026 · Revised Current SOCRadar reporting expands the scoping lens to 59.3M scanned hosts, 430,000+ targeted FortiGate firewalls, 90,000+ IP addresses, 750,000+ credentials, 105M+ records, 80,553 unique devices, 23,406 organizational domains, 260+ operation servers, and 659+ harvest cycles; keep those figures distinct from the earlier 73,932 URL dataset. 20-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 20 update date, says new compromised devices are being added, and retains the same 437K+/90K+/750K+/105M+ headline metrics.[25] [27] [35]
30-Jun-2026 · Revised SOCRadar states it attributes FortiBleed to Lynx / INC. 22-Jul-2026 · Added Newly retained; published >24h before this run: SOCRadar's public Volume II landing page now supports high-level operator/hierarchy, workflow, AI-assisted-operation, targeting, ATT&CK, and IoC-availability framing. Treat this as SOCRadar attribution and operation-structure context, not proof that every listed exposure, credential use, or downstream intrusion is attributable to that grouping.[12] [40]
2-Jul-2026 · Added SOCRadar now adds a ransomware-impact layer: it says FortiBleed infrastructure is directly connected to INC Ransom and Lynx ransomware operations, with admin-level access confirmed on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments from FortiBleed-derived access. 22-Jul-2026 · Added Newly retained; published >24h before this run: SOCRadar's public Volume II landing page now supports the higher-level operator, internal-workflow, AI-assisted-operation, targeting, ATT&CK, and IoC-availability framing that was previously caveated as pending a public whitepaper. Treat these as SOCRadar-reported findings, not a public victim list or proof for every exposed organization.[36] [40]
6-Jul-2026 · Added Freshly reported (<24h): UK press reporting adds a public-sector exposure cluster, saying FortiBleed-linked stolen-login activity affected UK Foreign Office and local-government account examples and citing NCSC Fortinet brute-force alerting. 7-Jul-2026 · Added Newly retained; published >24h before this run: NCSC's official June 18 alert directly supports UK-focused checker validation, IoC review, isolation/factory-reset escalation, shared-credential scoping, management-interface hardening, MFA, and PBKDF2 enforcement. Treat media reporting as public-sector scoping context, not a confirmed raw victim list or proof of successful compromise for every named organization.[37] [38] [39]
26-Aug-2026 · Added Newly retained; published >24h before this run: Canada's Cyber Centre official June 18 alert adds Canadian government guidance for Fortinet account inventory, suspicious-account removal, management-interface restriction, session termination, password resets, MFA, firmware review, and reporting matching activity through Cyber Centre channels. Treat it as official response guidance, not as a new victim list or confirmed compromise count.[45]
16-Aug-2026 · Added Newly retained; published >24h before this run: BGD e-GOV CIRT's July 7 advisory identifies 153 unique Bangladesh IP addresses associated with the FortiBleed tag. Treat this as regional exposure-scoping and investigation guidance, not a confirmed breach count or public victim list.[44]
27-Jul-2026 · Added Newly retained; published >24h before this run: CHT Security's first-party statement says its FortiBleed mention reflected FortiSupport Partner account use during customer product-registration/support workflows, and that CHT Security found no internal intrusion, data leak, or security impact. Treat this as deconfliction evidence for named-list handling, not as a public victim compromise confirmation.[41]
7-Aug-2026 · Added Newly retained; published >24h before this run: CybelAngel's June 25 flash-report summary adds a concrete persistence-review pivot: Fortinet-service-like administrator account names such as forticloud-sync, forticloud-tech, support_fortinet, fgtsecure, fgtsec, Technical_support, fortinetadmin, adminin, and tech-fortinet. Use these as local hunt terms, not proof of compromise by themselves.[42]
13-Aug-2026 · Added Newly retained; published >24h before this run: Roche's June 30 first-party advisory says two Roche-associated FortiGate devices appeared in the FortiBleed dataset, but Roche found no evidence of impact to Roche customer Laboratory Networks. Treat this as deconfliction and customer-impact boundary evidence, not proof of broader Roche, customer, or device compromise.[43]
23-Jun-2026 · Added SpyCloud Labs independently adds a multi-server access-broker infrastructure view, including broader non-Fortinet scanning and AI-assisted operator tooling; use it to widen hunting without publishing raw infrastructure, victim, or credential data.[29]
26-Jun-2026 · Added Newly retained Recorded Future/Insikt reporting adds seller-credibility deconfliction: it assesses SantaAd as likely credible while describing a separate low-credibility copycat or re-extortion effort. 5-Jul-2026 · Clarified Also use it as behavior-level workflow/infrastructure corroboration for private scoping, not to publish raw artifacts, acquisition paths, infrastructure, or victim details.[34]
23-Jun-2026 · Added Sophos now provides an official adjacent-device boundary: the same threat actors reportedly targeted internet-exposed Sophos Firewall appliances through user-level credential brute-forcing or stuffing, but Sophos had not observed Sophos Firewall compromise or exploitation of a Sophos Firewall vulnerability in reviewed telemetry.[30]
Organizations using FortiGate SSL VPN or internet-facing Fortinet administrative interfaces should treat this as an identity, remote-access, and configuration-review issue, not only a vulnerability-management ticket.[13] [14] [39] [45]
Scoping should start with owned domains, trusted FortiBleed checkers, public Fortinet/FortiGate URLs, Fortinet account exports, active SSL VPN/admin sessions, authentication logs, admin-change logs, MFA status, suspicious-account review, and password-rotation history.[10] [14] [39] [45]
No retained public source provides a reliable count of stolen Fortinet passwords successfully used against victims, or a reliable count of firewalls where attackers changed passwords, settings, or administrator accounts; those outcomes require local Fortinet telemetry.[8] [12] [13] [14] [16] [45]
A positive dataset or lookup hit should trigger urgent validation and containment, but dataset inclusion alone does not prove successful intrusion, data theft, or that every credential still works.[4] [6] [8] [10] [15] [16]
Executive Summary
FortiBleed is a reported large-scale Fortinet/FortiGate credential exposure tied to about 73,932 firewall or SSL VPN URLs worldwide, not a confirmed count of unique physical devices. Public reporting and Hudson Rock materials also cite roughly 21,632 affected domains and exposure across 194 countries, with records reportedly including usernames, email addresses, plaintext passwords in many cases, and some device-related metadata.[4] [5] [6] [9] [10] [16]
22-Jun-2026 · Added The June 22 AI Agent delta materially expands the story: SOCRadar and BleepingComputer now describe an active FortiBleed operation using a custom FortigateSniffer tool that abuses legitimate FortiOS diagnostic packet-sniffing functionality, parses captured traffic through SNIFTRAN/PCAP workflows, and feeds credentials or hashes into cracking and replay processes. 22-Jun-2026 · Revised SOCRadar reports 430,000+ targeted FortiGate firewalls, 260+ operation servers, 659+ harvest cycles, and collection across 24 protocols; those are active-operation metrics and should not be collapsed into the original 73,932 URL dataset.[25] [26] [27] [28]
30-Jun-2026 · Revised SOCRadar's June 29 update to its FortiBleed investigation page adds a source-level attribution change: SOCRadar says it attributes FortiBleed to Lynx / INC. 22-Jul-2026 · Added Newly retained; published >24h before this run: SOCRadar's public Volume II landing page now supports high-level operator/hierarchy, victim-workflow, AI-assisted-operation, targeting, ATT&CK, and IoC-availability framing. This brief retains the attribution as SOCRadar's current assessment while preserving the prior boundary: organizations still need local telemetry before assigning any specific exposure, successful login, persistence, data access, or downstream incident to that actor grouping.[12] [40]
2-Jul-2026 · Added SOCRadar's July 2 update materially raises the consequence framing: STRU says FortiBleed infrastructure is linked to INC Ransom and Lynx ransomware operations through a shared operator, overlapping victim data, and internal campaign tracking. SOCRadar reports roughly 11,250 FortiGate portals scanned across more than 150 countries in the expanded infrastructure, admin-level access confirmed on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments stemming from FortiBleed-derived access. This brief treats those as SOCRadar aggregate findings and continues to withhold raw indicators, infrastructure, victim details, credentials, recovered artifacts, and sensitive technical artifacts.[36] [40]
20-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows July 20 freshness, says new compromised devices are being added to the attacker database, and keeps the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics unchanged. Treat that as live-dataset freshness and continuing exposure-check relevance, not a new baseline count of unique devices or victims.[27]
6-Jul-2026 · Added Freshly reported (<24h): UK reporting adds a public-sector exposure cluster. The Times reports FortiBleed-linked stolen-login activity affecting UK Foreign Office and council examples, while The Sun reports a list seen by The Telegraph included overseas Foreign Office and local-government staff examples and says NCSC issued Fortinet brute-force alerting. This brief retains that as reported scoping context and alert urgency, not as a raw victim list, credential publication, or proof of successful compromise for every named organization.[37] [38]
7-Jul-2026 · Added Newly retained; published >24h before this run: NCSC's June 18 official alert now directly supports the UK response layer. It tells organizations using Fortinet edge devices with SSL VPN enabled to investigate potential malicious activity, use FortiBleed checkers, review IoCs, isolate devices where compromise evidence exists, consider factory reset when persistence is possible, investigate shared credentials and reachable devices, harden management exposure, enforce MFA, and enable PBKDF2 for admin-interface credential storage.[39]
26-Aug-2026 · Added Newly retained; published >24h before this run: Canada's Cyber Centre official June 18 alert adds a Canadian public-sector response layer. It says the Cyber Centre became aware on June 17 of open-source FortiBleed reporting affecting Fortinet firewalls and VPN gateways, warns exposed credentials could allow remote access or security-control modification, and recommends account inventory, suspicious-account removal, management-interface restriction, session termination, password resets, MFA, firmware review, internet-gateway defense, privilege-management, and reporting matching activity to the Cyber Centre.[45]
23-Jun-2026 · Revised The sniffer evidence should be read as a post-compromise harvesting loop, not as proof of the first entry method. The supported working theory is that attackers first obtain administrative, SSH, web-admin, or VPN-level access through exposed or reused credentials, brute-force/credential-validation activity, prior leaks, infostealer-derived material, historical vulnerability exposure, or another access path. After that access exists, FortigateSniffer reportedly abuses FortiOS's legitimate diagnostic packet-capture capability to observe credential-bearing traffic, convert or parse captures, extract additional credentials or hashes, and feed cracking/replay workflows.[13] [25] [26] [28]
24-Jun-2026 · Added Arctic Wolf's reverse-engineering report makes the technical scoping more concrete by describing a recovered CyberStrike Harvester binary and associated tooling for credential stuffing, password spraying, configuration harvesting, offline cracking, post-authentication capture processing, AD/SMB access, credential cleaning, and cracking automation. 27-Jun-2026 · Revised Unit 42's publication date is now verified as June 26; it adds customer-telemetry evidence of suspicious login attempts and MSSQL targeting, while explicitly stating the activity was not targeting Palo Alto Networks devices. SANS reinforces that compromised perimeter devices require review of the traffic visible to the device.[31] [32] [33]
23-Jun-2026 · Added SpyCloud's infrastructure analysis expands the scoping lens beyond Fortinet-only validation: it describes brute-force, operator-workstation, and cracking infrastructure roles, broader Synology/Sophos/MSSQL targeting, AI-assisted tooling, and marketplace signal around an access-broker account. Use that as hunt expansion, not as permission to publish server identifiers, victim details, marketplace artifacts, or sensitive exfiltration descriptions.[29]
23-Jun-2026 · Added Sophos adds a narrower but practical adjacent-device warning: the same threat actors also targeted internet-exposed Sophos Firewall appliances, but Sophos frames that activity as user-level credential brute-forcing or stuffing against appliances that lacked MFA protection. Sophos had not seen indications of compromise in reviewed telemetry and had not seen evidence of Sophos Firewall vulnerability exploitation. For scoping, this means a Sophos VPN/firewall call involving valid credentials may be FortiBleed-adjacent, but it should not be called FortiBleed without corroborating local evidence.[30]
The evidence described in retained reporting centers on discovered servers or attacker-controlled lists containing FortiGate passwords that appeared potentially valid or tested. The Diachenko LinkedIn post provides the key social-source discovery signal, Hudson Rock provides the lookup and disclosure workflow, SOCRadar describes operational infrastructure, and Kevin Beaumont analysis emphasizes that configuration-export or device-access questions remain unresolved.[9] [10] [11] [12] [15]
The operational risk is concentrated at the network edge, especially FortiGate SSL VPN services and internet-exposed Fortinet administrative interfaces. If exposed credentials are current or reused, attackers may be able to access VPN or firewall administration paths, support persistence, or move deeper into enterprise environments without relying on a new software exploit.[3] [4] [8]
Two outcome questions remain unresolved in public reporting: how many stolen Fortinet passwords were actually used against victims, and how many firewalls had passwords, administrator accounts, security policies, or other settings changed by attackers. The public record supports exposure and plausible access risk, but those outcome counts require organization-specific Fortinet VPN logs, firewall-administration logs, active-session records, password-change history, administrator-account history, and configuration-change evidence.[8] [12] [13] [14] [16] [45]
The strongest decision frame is identity and access control, not a single patchable flaw. Fortinet states the activity is not a new Fortinet vulnerability and is not related to a recent incident or advisory; CISA nevertheless urges Fortinet customers to terminate active SSL VPN and administrative sessions, reset VPN and administrator passwords, enable phishing-resistant MFA, and review logs. UK NCSC and Canada's Cyber Centre reinforce the same regional-government posture: investigate exposed Fortinet edge devices, restrict management access, inventory accounts, remove suspicious accounts, and escalate when compromise evidence appears.[13] [14] [39] [45]
Scoping teams should inventory public Fortinet/FortiGate URLs and domains, check whether domains appear in the Hudson Rock lookup portal, and validate findings against internal account, VPN, admin-login, active-session, and configuration-change records. A positive lookup should trigger urgent validation and containment; a negative lookup should not be treated as proof of safety because external datasets are partial views of exposure.[10] [14] [39] [45]
AI Agent Delta Updates
September 2, 2026 8:12 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: September 2, 2026 8:12 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 2-Sep-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check and investigation pages, BleepingComputer FortiBleed/FortigateSniffer/Fortinet tag pages, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, HKCERT, Nigeria CERT, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, UpGuard, eSentire, MINE2, CERT-PH/DICT social advisory snippets, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified after the September 1 monitor run. Newly observed September 1-September 2 items were unrelated Fortinet corporate or product-security pages, event/webinar and category wrappers around older FortiBleed reporting, current-site-date wrappers around June/July FortiBleed content, the August 31 MINE2 vendor-analysis post that restated already retained Unit 42/Recorded Future/Fortinet/SOCRadar/SecurityWeek claims and added product-specific deception recommendations that were not retained as FortiBleed source evidence, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Picus/Huntress/CSA/UpGuard/eSentire context already represented or previously rejected, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. Fortinet's public PSIRT article remained dated June 19, 2026; CISA's public FortiBleed alert remained June 2026; BleepingComputer's latest FortiBleed tag entries remained June 22 and July 1 reporting; SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable September 2 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.5. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET. Fortinet/CISA/NCSC/Canadian Cyber Centre remain controlling for official vulnerability-status and hardening language. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, 1 no-change/all-check eligible subscriber, and 1 Slack-enabled subscriber. No external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy.
September 1, 2026 8:06 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: September 1, 2026 8:06 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 1-Sep-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check and investigation pages, BleepingComputer FortiBleed/FortigateSniffer/Fortinet tag pages, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, HKCERT, Nigeria CERT, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, UpGuard, CERT-PH/DICT social advisory snippets, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified after the August 31 monitor run. Newly observed August 31-September 1 items were unrelated Fortinet stock/company or security-news pages, product-release wrappers around older FortiBleed reporting, current-site-date wrappers around June/July FortiBleed content, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Picus/Huntress/CSA/UpGuard context already represented or previously rejected, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. Fortinet's public PSIRT article remained dated June 19, 2026; CISA's public FortiBleed alert remained June 2026; BleepingComputer's latest FortiBleed tag entries remained June 22 and July 1 reporting; UpGuard's release note was dated June 25, 2026 and added no material public finding beyond existing scoping guidance. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.5. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET. Fortinet/CISA/NCSC/Canadian Cyber Centre remain controlling for official vulnerability-status and hardening language. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, 1 no-change/all-check eligible subscriber, and 1 Slack-enabled subscriber. No external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy.
August 31, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 31, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 31-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check and FortiBleed investigation pages, BleepingComputer Fortinet/FortiGate/FortiBleed tag pages, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, HKCERT, Nigeria CERT, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, Fortinet late-August blog/news items, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 30-August 31 items were current-site-date wrappers around older June FortiBleed reporting, Fortinet event/corporate pages unrelated to FortiBleed, SOCRadar ransomware-intelligence and navigation pages where FortiBleed appeared as site chrome, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/HKCERT/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, and unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 31 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.5. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC/Canadian Cyber Centre remain controlling for official vulnerability-status and hardening language. Active subscriber count was queried with 0 active subscribers, 0 email-enabled subscribers, 0 Slack-enabled subscribers, and 0 no-change/all-check eligible subscribers. Subscriber delivery and admin email workflows were intentionally not used: no external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy.
August 30, 2026 8:01 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 30, 2026 8:01 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 30-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check and FortiBleed investigation pages, BleepingComputer Fortinet/FortiGate/FortiBleed tag pages, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, Fortinet late-August blog/news items, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 29-August 30 items were Fortinet corporate/product/security pages unrelated to FortiBleed, SOCRadar blog or navigation pages with already represented June/July FortiBleed metrics, BleepingComputer Fortinet tag entries whose newest FortiBleed-specific items remained the July 1 ransomware-link story and older June reporting, Unit 42's August 18 TheHatman addition that did not revise its already retained FortiBleed-specific section, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, and unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 30 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.5. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC/Canadian Cyber Centre remain controlling for official vulnerability-status and hardening language. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, 1 no-change/all-check eligible subscriber, and 1 Slack-enabled subscriber, but no external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy.
August 29, 2026 8:04 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 29, 2026 8:04 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 29-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check and FortiBleed investigation pages, BleepingComputer FortiBleed and FortiGate tag pages, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, Fortinet August blog/news items, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 28-August 29 items were Fortinet corporate/public-private-partnership or deployment-guide pages unrelated to FortiBleed, CERT-In site-footer freshness around the unchanged June 18 FortiBleed current-activity entry, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, and unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 29 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.5. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC/Canadian Cyber Centre remain controlling for official vulnerability-status and hardening language. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, 1 no-change/all-check eligible subscriber, and 1 Slack-enabled subscriber, but no external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy.
August 28, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 28, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 28-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, marketing, and IOC Radar/navigation pages, BleepingComputer FortiBleed and FortigateSniffer reporting/tag pages, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, Fortinet August blog/news items, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 27-August 28 items were Fortinet corporate, partner, or product-security pages unrelated to FortiBleed, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 28 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.5. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC/Canadian Cyber Centre remain controlling for official vulnerability-status and hardening language. Subscriber count query was unavailable because local Supabase URL/service-role credentials were not present. No external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, retry workflow, or notification workflow was used under the automation no-email policy.
August 27, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 27, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 27-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting/tag pages, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, SOCRadar IOC Radar/navigation results, Fortinet August blog/news items, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 26-August 27 items were Fortinet corporate or product-security posts unrelated to FortiBleed, SOCRadar navigation/IOC Radar pages where FortiBleed appeared only in site chrome, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 27 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.5. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC/Canadian Cyber Centre remain controlling for official vulnerability-status and hardening language. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, and 1 no-change/all-check eligible subscriber, but subscriber notification was not sent and no external email, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 26, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 26, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 26-Aug-2026 · Added Evidence / Change: Source-backed delta found. Newly retained; published >24h before this run: Canadian Centre for Cyber Security alert AL26-014, published and date-modified June 18, 2026, was newly retained after deconfliction against the static page, existing citations, prior AI Monitoring Agent delta entries, and this run's missing automation memory file. The alert says the Cyber Centre became aware on June 17, 2026 of open-source FortiBleed reporting involving exposed credentials affecting Fortinet firewalls and VPN gateways, warns those credentials could enable remote access or modification of security controls, and recommends account inventory, suspicious-account removal, management-interface restriction, session termination, password resets, MFA, firmware review, internet-gateway defense, privilege-management, and reporting matching activity to the Cyber Centre. Revisited Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Tesorion, BrightTalk/SOCRadar webinar listings, Techjack, Orca, Aviatrix, eSentire, search-index-only pages, social/video posts, and related public reporting. Newly observed August 25-August 26 items were mostly event listings, current-site-date wrappers, recrawled older FortiBleed articles, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Unit 42/CSA/Bitdefender/Picus/Huntress context, FortiBleed-as-comparator material, SEO rewrites, or unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 26 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Timeline, Source Reconciliation, About the Contributors, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: Incremented to v4.5. Retain Canadian Centre for Cyber Security as official Canadian response guidance; do not treat it as a new victim list, raw credential source, compromise count, or Fortinet CVE finding. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, and 1 all-check subscriber, but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.[45]
August 25, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 25, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 25-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Tesorion, BrightTalk/SOCRadar webinar listings, Techjack, Orca, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 24-August 25 items were unrelated security-news or Fortinet-adjacent pages; FortiBleed event/webinar listings without new public findings; current-site-date wrappers around older FortiBleed reporting; older June/July/August FortiBleed reporting recrawled today; duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources; FortiBleed-as-comparator material; social amplification; SEO rewrites; or unsupported FortiBleed-to-CVE conflation. Fortinet public pages did not surface a newer FortiBleed-specific PSIRT update, CISA/NICCS did not add a FortiBleed-specific advisory, Unit 42's August 18 update remained a broader credential-attack/product-protection addition without a new FortiBleed finding, and SOCRadar FortiBleed Check retained already represented headline metrics without a verifiable August 25 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.4. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, active subscriber count was queried with 2 active subscribers and 1 all-check subscriber but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 24, 2026 8:08 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 24, 2026 8:08 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 24-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Tesorion, BrightTalk/SOCRadar webinar listings, Techjack, Orca, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 23-August 24 items were unrelated Fortinet or security-news pages; webinar listings without new public FortiBleed findings; current-site-date wrappers around older FortiBleed reporting; older June/July/August FortiBleed reporting recrawled today; FortiBleed-as-comparator material; SOCRadar ransomware-intelligence pages where FortiBleed appeared as navigation/tool chrome rather than a FortiBleed update; duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources; social amplification; SEO rewrites; or unsupported FortiBleed-to-CVE conflation. Fortinet's public blog index still showed the June 19 PSIRT FortiBleed analysis as the newest PSIRT FortiBleed-specific item. Unit 42's August 18 update remained a TheHatman/product-protection addition and did not revise the already retained FortiBleed-specific section. Tesorion's August 19 roundup pointed back to already represented SOCRadar, Fortinet, and SANS material. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 24 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.4. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, active subscriber count was queried with 2 active subscribers and 1 all-check subscriber but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 23, 2026 8:07 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 23, 2026 8:07 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 23-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Provintell/CODERED index material, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 22-August 23 items were unrelated security-news pages; current-site-date wrappers around older FortiBleed reporting; older June/July/August FortiBleed reporting recrawled today; FortiBleed-as-comparator material; duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources; social amplification; SEO rewrites; or unsupported claims. CERT-In search snippets showed Last Updated On August 23, 2026 while the accessible FortiBleed-specific activity remained unavailable or dated June 18, 2026. Unit 42's August 18 update remained a TheHatman/product-protection addition and did not revise the already retained FortiBleed-specific section. The420's August 13 story duplicated already represented reporting without stronger primary evidence. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 23 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.4. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, subscriber count query was blocked by missing local Supabase URL/service-role credentials, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 22, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 22, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 22-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, CERT-In, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Provintell/CODERED index material, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 21-August 22 items were unrelated Fortinet, Cisco, GitLab, OpenAI, and security-news pages; current-site-date wrappers around older FortiBleed reporting; older June/July/August FortiBleed reporting recrawled today; FortiBleed-as-comparator material; duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources; social amplification; SEO rewrites; or unsupported claims. CERT-In's page footer showed Last Updated On August 22, 2026 while the FortiBleed activity remained dated June 18, 2026. Unit 42's August 18 update remained a TheHatman/product-protection addition and did not revise the already retained FortiBleed-specific section. The420's August 13 story and Provintell's August 22 index wrapper duplicated already represented reporting without stronger primary evidence. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 22 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.4. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, active subscriber count was queried with 2 active subscribers and 1 all-check subscriber but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 21, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 21, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 21-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 20-August 21 items were unrelated Fortinet or security-news pages, current-site-date wrappers around older FortiBleed reporting, older June/July FortiBleed reporting recrawled today, FortiBleed-as-comparator material, duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources, social amplification, SEO rewrites, or unsupported claims. Unit 42's August 18 update remained a TheHatman/product-protection addition and did not revise the already retained FortiBleed-specific section. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 21 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.4. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, subscriber count query was unavailable because local Supabase service credentials were not present, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 20, 2026 8:13 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 20, 2026 8:13 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 20-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 19-August 20 items were unrelated Fortinet/frontier-AI or security-news pages, webinar listings, current-site-date wrappers around older FortiBleed reporting, older June/July FortiBleed reporting recrawled today, FortiBleed-as-comparator material, duplicate SOCRadar/Hudson Rock/BleepingComputer/CSA/CERT-In/Arete/ZenoX/CybersecurityNews ransomware-link or FortigateSniffer context already represented by retained sources, duplicate regional government/social advisories, social amplification, SEO rewrites, or unsupported claims. Unit 42's August 18 update added TheHatman credential-attack content and product-protection guidance but did not revise the already retained FortiBleed-specific section; CERT-In's page footer showed Last Updated On August 20, 2026 while the FortiBleed activity remained dated June 18. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 20 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps, home monitor status Action Required: No version increment; current version remains v4.4. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, subscriber count was unavailable because local Supabase service credentials were not present, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 19, 2026 8:01 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 19, 2026 8:01 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 19-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, TAKA Alliance Bangladesh recap, Arete, SecurityWeek, S-RM, Censys, CERT-PH/DICT social advisory snippets, ResearchGate/BrightTALK/Zscaler webinar references, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 18-August 19 items were unrelated Fortinet/frontier-AI or security-news pages, webinar listings, current-site-date wrappers around older FortiBleed reporting, older June/July FortiBleed reporting recrawled today, FortiBleed-as-comparator material, duplicate SOCRadar/Hudson Rock/BleepingComputer/CSA/CERT-In/Arete ransomware-link context already represented by retained sources, duplicate regional government/social advisories, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 19 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.4. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, subscriber count was unavailable in the local environment, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 18, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 18, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 18-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, TAKA Alliance Bangladesh recap, Arete, SecurityWeek, S-RM, ResearchGate/BrightTALK webinar references, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 17-August 18 items were unrelated Fortinet/company/security news, government-site footer or recrawl freshness without new FortiBleed findings, older June/July FortiBleed reporting recrawled today, domain-specific lookup-result snippets unsuitable for publication, FortiBleed-as-comparator material, duplicate SOCRadar/Hudson Rock/BleepingComputer/CSA/CERT-In/Arete ransomware-link context already represented by retained sources, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 18 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.4. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, subscriber all-check recipient count was queried but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 17, 2026 8:07 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 17, 2026 8:07 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 17-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, TAKA Alliance Bangladesh recap, Memeburn, CyberNexora, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 16-August 17 items were unrelated Fortinet/company/security news, SOCRadar navigation or ransomware-profile pages that used FortiBleed only as a site/nav/comparator signal, older June/July FortiBleed reporting recrawled today, duplicate BGD e-GOV CIRT Bangladesh scoping recaps, duplicate Hudson Rock/InfoStealers republishing, current-site-date wrappers around older reporting, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 17 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.4. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 16, 2026 8:08 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 16, 2026 8:08 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 16-Aug-2026 · Added Evidence / Change: Source-backed delta found. Newly retained; published >24h before this run: BGD e-GOV CIRT's July 7 advisory identifies 153 unique Bangladesh IP addresses associated with the FortiBleed tag and requiring investigation. Revisited FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, ngCERT search results, SOCRadar webinar listings, search-index-only pages, social/video posts, and related public reporting. Newly observed August 15-August 16 items were mostly unrelated Fortinet/company/security news, current-site-date wrappers around older FortiBleed reporting, FortiBleed-as-comparator content, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel/Picus context, vendor/product pages, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 16 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, BLUF, Source Reconciliation, Public Victims / Disclosure Matrix, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v4.4. Retain BGD e-GOV CIRT as regional CERT scoping evidence; do not publish raw addresses, infer confirmed compromise for all 153 tagged IPs, or treat Bangladesh-specific exposure tagging as a victim list. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.[44]
August 15, 2026 8:08 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 15, 2026 8:08 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 15-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard/community pages, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, Fortinet packet-sniffer documentation, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 14-August 15 items were Fortinet company/product news unrelated to FortiBleed, Fortinet support/community or packet-sniffer content that did not change the campaign brief, older June/July FortiBleed reporting recrawled today, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel/Picus context already represented, FortiBleed-as-comparator material, vendor/product pages, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 15 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.3. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 14, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 14, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 14-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 13-August 14 items were Fortinet stock/company news unrelated to FortiBleed, Fortinet packet-sniffer documentation unrelated to the FortigateSniffer campaign tool, older June/July FortiBleed reporting recrawled today, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context already represented, FortiBleed-as-comparator material, vendor/product pages, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 14 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.3. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 13, 2026 8:12 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 13, 2026 8:12 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 13-Aug-2026 · Added Evidence / Change: Source-backed delta found. Newly retained; published >24h before this run: Roche Diagnostics' June 30 first-party advisory says its investigation identified two Roche-associated FortiGate devices in the FortiBleed dataset and found no evidence of impact to Roche customer Laboratory Networks. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, CERT-In, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Roche, Site24x7, Cybernews/Gunra reporting, social/video posts, search-index-only pages, and related public reporting. CERT-In current-activity content dated June 18 duplicated existing government-warning and hardening context; Site24x7 was newly observed but not retained because the trust-center text lacked a verifiable FortiBleed publication/update timestamp; Cybernews/Gunra reporting was treated as unrelated Fortinet CVE/ransomware context with FortiBleed used only as background. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 13 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, BLUF, Timeline, Source Reconciliation, Real World Examples, Public Victims / Disclosure Matrix, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v4.3. Retain Roche as first-party deconfliction and customer-impact boundary evidence; do not infer broader Roche compromise, customer compromise, raw credential validity, or dataset-row details. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.[43]
August 12, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 12, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 12-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Censys, The Register, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 11-August 12 items were duplicate summaries, older June/July reporting recrawled today, FortiBleed-as-comparator material, unrelated Fortinet CVE/ransomware reporting, Fortinet product/security pages unrelated to this credential-exposure brief, social amplification, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. Censys' June 19 advisory was newly noticed but not retained because it repeats already represented Fortinet/Hudson Rock/credential-exposure and hardening guidance. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 12 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.2. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 11, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 11, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 11-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, search-index-only pages, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 10-August 11 items were duplicate summaries, blocked/unverifiable browser-check pages, older June/July reporting recrawled today, FortiBleed-as-comparator material, Fortinet product/security pages unrelated to this credential-exposure brief, social amplification, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 11 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.2. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 10, 2026 8:04 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 10, 2026 8:04 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 10-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, Security Affairs tag/archive pages, Hudson Rock search-result pages, social/video posts, search-index-only pages, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 9-August 10 items were duplicate summaries, older SOCRadar FAQ/checker content already represented by current no-new-CVE, credential-reuse, PBKDF2, active-operation, and exposure-check language, FortiBleed-as-comparator material, vendor/product pages unrelated to the FortiBleed brief, social amplification, search-index recrawls, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 10 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.2. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 9, 2026 8:05 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 9, 2026 8:05 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 9-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, Security Affairs tag/archive pages, Hudson Rock search-result pages, social/video posts, search-index-only pages, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 8-August 9 items were duplicate summaries, domain-specific lookup-result snippets not suitable for publication, FortiBleed-as-comparator material, vendor/product pages unrelated to the FortiBleed brief, social amplification, search-index recrawls, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 9 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.2. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 8, 2026 8:04 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 8, 2026 8:04 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 8-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, GBHackers, Rescana, Orca Security, CybersecurityNews, SecurityOnline, CSO Online, IndustrialCyber, ITPro, Portnox, ITBriefcase, Infosec.ge, LinkedIn/social/video posts, search-index-only pages, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 7-August 8 items were duplicate summaries, weekly roundups, FortiBleed-as-comparator material, vendor/product pages unrelated to the FortiBleed brief, social amplification, search-index recrawls, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 8 checker update timestamp in retrieved page text. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.2. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 7, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 7, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 7-Aug-2026 · Added Evidence / Change: Source-backed delta found. Newly retained; published >24h before this run: CybelAngel's June 25 public flash-report summary was newly retained after deconfliction against the static page, existing citations, and prior delta rows. It adds source-backed planted-account hunting names for Fortinet-service-like administrator accounts, including forticloud-sync, forticloud-tech, support_fortinet, fgtsecure, fgtsec, Technical_support, fortinetadmin, adminin, and tech-fortinet. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, GBHackers, Rescana, Orca Security, CybersecurityNews, SecurityOnline, CSO Online, IndustrialCyber, ITPro, social/video posts, search-index-only pages, and related public reporting. Newly observed August 6-August 7 items were duplicate summaries, source-index freshness without page-backed FortiBleed changes, unrelated Fortinet/company/security pages, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported CVE/attribution claims not retained as citations. Affected Cards: AI Agent Delta Updates, BLUF, Timeline, Response Playbook, IOCs / Observables, Threat Actor Glossary, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v4.2. Treat CybelAngel account names as local persistence-review pivots after an exposure match; do not publish raw infrastructure, victim rows, credentials, sensitive dataset excerpts, acquisition paths, or unsupported FortiBleed CVE claims. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.[42]
August 6, 2026 8:04 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 6, 2026 8:04 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 6-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CSO Online, IndustrialCyber, ITPro, social/video posts, search-index-only pages, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 5-August 6 items were Fortinet corporate/product/security pages unrelated to FortiBleed findings, SOCRadar webinar/event listings and IOC/free-tool navigation that did not add retained technical findings, crawled-today duplicate June/July FortiBleed reporting, DataBreachToday/BankInfoSecurity and Cybersecurity Dive duplicates of already represented July 2 SOCRadar Lynx/INC linkage, CybersecurityNews and SecurityOnline pages with current site dates but June publication dates, duplicate Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 5, 2026 8:01 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 5, 2026 8:01 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 5-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, and whitepaper pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, search-index-only pages, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 4-August 5 items were Fortinet corporate/product/security pages unrelated to FortiBleed findings, crawled-today duplicate June/July FortiBleed reporting, SOCRadar free-tool and campaign pages already represented in citations 27 and 35, the already represented SOCRadar investigation page showing a July 31 page date without a new retained finding, duplicate Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. No newly added source was retained; freshness labels applied to retained sources: none. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 4, 2026 8:01 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 4, 2026 8:01 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 4-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, search-index-only pages, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 3-August 4 items were crawled-today older reporting, SOCRadar free-tool/IOC pages unrelated to FortiBleed findings, the already represented SOCRadar investigation page showing a July 31 page date without a new retained finding, duplicate Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 4 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 3, 2026 8:01 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 3, 2026 8:01 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 3-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, search-index-only pages, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 2-August 3 items were crawled-today older reporting, SOCRadar free-tool/IOC pages unrelated to FortiBleed findings, FortiGuard ransomware profile content unrelated to FortiBleed, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 3 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 2, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 2, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 2-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed August 1-August 2 items were crawled-today older reporting, source tag pages, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, unrelated Fortinet company or vulnerability content, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 2 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.
August 1, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: August 1, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 1-Aug-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont/DoublePulsar, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed July 31-August 1 items were crawled-today older reporting, source tag pages, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, unrelated Fortinet company or vulnerability content, FortiBleed-as-comparator material, SEO rewrites, social/video posts, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 1 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy.
July 31, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 31, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 31-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, BankInfoSecurity, Cyber Press, SecurityOnline, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed July 30-July 31 items were crawled-today older reporting, broader VPN/ransomware or edge-infrastructure context, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, unrelated Fortinet company or vulnerability content, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 31 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy.
July 30, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 30, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 30-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, ITPro, IndustrialCyber, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed July 29-July 30 items were crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, unrelated Fortinet company or vulnerability content, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 30 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy.
July 29, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 29, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 29-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, PatriotGIS, Cloud Security Alliance, Bitdefender, The Hacker News, social/video posts, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed July 28-July 29 items were business-oriented recaps, crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Recorded Future/Unit 42/Hudson Rock/BleepingComputer context already represented, unrelated Fortinet industry-trend content, social posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 29 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy.
July 28, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 28, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 28-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, CyberScoop, Wyden Senate letter, CUInfoSecurity, CybersecurityNews, The Hacker News, Dark Reading, BankInfoSecurity, Cloud Security Alliance, and related public reporting. No source-backed FortiBleed content delta was identified. Newly observed July 27-July 28 items were policy/legacy-VPN context referencing FortiBleed, crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/Unit 42/Hudson Rock/BleepingComputer context already represented, unrelated Fortinet vulnerability news, social posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 28 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment; current version remains v4.1. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy.
July 27, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 27, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 27-Jul-2026 · Added Evidence / Change: Source-backed delta found. Newly retained; published >24h before this run: CHT Security's July 25 first-party clarification states its name appeared in recent FortiBleed intelligence reporting because a FortiSupport Partner account was used for prior customer product-registration and technical-support workflows, not because its internal environment was compromised. Freshly reported (<24h) July 27 Taiwan media coverage repeated the clarification and was treated as duplicate amplification rather than a separate substantive source. Revisited Fortinet PSIRT/FortiGuard, CISA, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, CybersecurityNews, CHT Security, Taiwan media reporting, The Hacker News, Dark Reading, and related public reporting. CybersecurityNews July 27 edge-VPN reporting duplicated existing FortiBleed remote-access/ransomware context; SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 27 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, BLUF, Real World Examples, Public Victims / Disclosure Matrix, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v4.1. Retain CHT Security as first-party deconfliction evidence for named-list handling; do not infer CHT Security compromise, customer compromise, raw credential validity, or dataset-row details. No external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy.[41]
July 26, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 26, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 26-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, IndustrialCyber, Cloud Security Alliance, Bitsight, Bitdefender, Shadowserver, Business Recorder/Pakistan National CERT reporting, Preferred Data, Penligent, The Hacker News, Dark Reading, and related public reporting. No source-backed content delta was identified. Newly observed July 25-July 26 items were crawled-today older reporting, SMB-oriented Fortinet July patch/FortiBleed recap content, duplicate SOCRadar/Fortinet/CISA/Unit 42/Hudson Rock/BleepingComputer context already represented, SEO rewrites, social posts, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 26 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, or notification was sent under the automation no-email policy.
July 25, 2026 8:00 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 25, 2026 8:00 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 25-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, IndustrialCyber, Cloud Security Alliance, Bitsight, Bitdefender, Pakistan National CERT reporting via Business Recorder, Shadowserver, and related public reporting. No source-backed content delta was identified. Newly observed July 24-July 25 items were broader VPN/ransomware context, older regional CERT/media reporting, crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/Recorded Future context already represented, SEO rewrites, social posts, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 25 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, or notification was sent under the automation no-email policy.
July 24, 2026 8:01 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 24, 2026 8:01 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 24-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, IndustrialCyber, Cloud Security Alliance, Bitsight, Bitdefender, and related public reporting. No source-backed content delta was identified. Newly observed July 23-July 24 items were broader VPN/ransomware context, crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/Recorded Future context already represented, SEO rewrites, social posts, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 24 checker update timestamp in retrieved page text. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, or notification was sent under the automation no-email policy.
July 23, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 23, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 23-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA, UK NCSC, WaterISAC, Security Affairs, Kevin Beaumont, Diachenko, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, IndustrialCyber, Cloud Security Alliance, Risky Business, Bitsight, Security Boulevard, and related public reporting. No source-backed content delta was identified. Newly observed July 22-July 23 items were crawled-today older reporting, unrelated security news, duplicate SOCRadar/BleepingComputer/Unit 42/Risky Business context already represented, SEO rewrites, social posts, or unsupported claims. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, or notification was sent under the automation no-email policy.
July 22, 2026 8:04 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 22, 2026 8:04 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 22-Jul-2026 · Added Evidence / Change: Source-backed delta found. Newly retained; published >24h before this run: SOCRadar's public FortiBleed Unmasked Volume II landing page is now retained as source 40 after search/open verification on July 22, 2026 at 8:04 AM ET. The page removes the prior pending-public-whitepaper caveat and supports high-level FortiBleed-to-Lynx/INC linkage, operator and hierarchy analysis, victim-workflow mapping, AI-assisted offensive operations, technical profiling, targeting analysis, ATT&CK mapping, and IoC availability. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar, BleepingComputer, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, IndustrialCyber, Cloud Security Alliance, The Hacker News, Arete, and related public reporting; other newly observed July 21-July 22 items were unrelated Fortinet advisories, blocked/member-only resources, duplicate summaries, search-index freshness without page-backed changed findings, or unsupported claims. Affected Cards: AI Agent Delta Updates, BLUF, Source Reconciliation, About the Contributors, Real World Examples, Threat Actor Glossary, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v4.0. Retain Volume II as SOCRadar source-backed attribution and operation-structure context only; do not republish raw IoCs, victim details, infrastructure, recovered artifacts, credentials, or acquisition paths. No external email, subscriber alert, or notification was sent under the automation no-email policy.[40]
July 21, 2026 8:01 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 21, 2026 8:01 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 21-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar, BleepingComputer, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, Singapore CSA, ASD ACSC, Security Affairs, Kevin Beaumont, Diachenko, WaterISAC, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, IndustrialCyber, Cloud Security Alliance, SecurityWeek, The Hacker News, Arete, Bitdefender, and related public reporting. No source-backed content delta was identified. SOCRadar FortiBleed Check did not show a verifiable July 21 checker update in retrieved page text and retained the already represented 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics; newly observed July 20-July 21 items were duplicate recaps, older summaries, search-index freshness without page-backed changed findings, unrelated Fortinet vulnerability material, blocked/social pages, or unsupported claims. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, Fortinet/CISA/NCSC remain controlling for official vulnerability-status and hardening language, and no external email, subscriber alert, or notification was sent under the automation no-email policy.
July 20, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 20, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 20-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 20 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, Singapore CSA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, IndustrialCyber, Cloud Security Alliance, SecurityWeek, The Hacker News, Lawfare/Risky Business, Arete, Bitdefender, FortiGuard PSIRT, and related public reporting; newly observed July 19-July 20 items were checker freshness, already represented official guidance, older or duplicate summaries, unrelated Fortinet vulnerability advisories, blocked pages, or unsupported claims not retained as additional citations. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.9. Treat the July 20 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions. Next scheduled run remains daily at 12:00 PM ET. No external email, subscriber alert, or notification was sent under the automation no-email policy.[27]
July 19, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 19, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 19-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 19 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, Singapore CSA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, IndustrialCyber, Cloud Security Alliance, SecurityWeek, The Hacker News, Lawfare/Risky Business, Arete, Bitdefender, FortiGuard PSIRT, and related public reporting; newly observed July 18-July 19 items were checker freshness, already represented official guidance, older or duplicate summaries, unrelated Fortinet vulnerability advisories, blocked pages, or unsupported claims not retained as additional citations. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.8. Treat the July 19 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions. Next scheduled run remains daily at 12:00 PM ET. No external email, subscriber alert, or notification was sent under the automation no-email policy.[27]
July 18, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 18, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 18-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 18 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, Singapore CSA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, IndustrialCyber, Cloud Security Alliance, SecurityWeek, The Hacker News, Lawfare/Risky Business, DIESEC, and related public reporting; newly observed July 17-July 18 items were checker freshness, FortiBleed-as-comparator edge-infrastructure commentary, already represented official guidance, older or duplicate summaries, blocked pages, or unsupported claims not retained as additional citations. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.7. Treat the July 18 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions. Next scheduled run remains daily at 12:00 PM ET. No external email, subscriber alert, or notification was sent under the automation no-email policy.[27]
July 17, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 17, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 17-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 17 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, Singapore CSA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, IndustrialCyber, Cloud Security Alliance, SecurityWeek, The Hacker News, The Times, The Sun, and related public reporting; newly observed July 16-July 17 items were checker freshness, already represented official guidance, older or duplicate summaries, blocked pages, or unsupported claims not retained as additional citations. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.6. Treat the July 17 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions. Next scheduled run remains daily at 12:00 PM ET.[27]
July 16, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 16, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 16-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 16 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Qualys, ITPro, IndustrialCyber, CybersecurityNews, SecurityWeek, The Hacker News, The Times, The Sun, Risky Business, RootVector, social/video posts, and related public reporting; newly observed July 15-July 16 items were checker freshness, already represented SOCRadar/Risky Business AI-enabled-operation commentary, older or duplicate summaries, social/video posts, or unverifiable claims not retained as additional citations. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.5. Treat the July 16 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions.[27]
July 15, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 15, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 15-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 15 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Qualys, ITPro, IndustrialCyber, CybersecurityNews, SecurityWeek, The Hacker News, The Times, The Sun, RH-ISAC, Hunter Strategy, Picus, Help Net Security, and related public reporting; newly observed July 14-July 15 items were checker freshness, older or already represented summaries, unrelated Fortinet PSIRT items, blocked/member-only/social pages, or duplicate recaps already represented by retained sources. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.4. Treat the July 15 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions.[27]
July 14, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 14, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 14-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 14 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Qualys, ITPro, IndustrialCyber, CybersecurityNews, SecurityWeek, The Hacker News, The Times, The Sun, Cyber News Centre, and related public reporting; newly observed July 13-July 14 items were checker freshness, older Hudson Rock/InfoStealers detail already represented by retained sources, unrelated Fortinet PSIRT items, blocked/social pages, or duplicate recaps already represented by retained sources. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.3. Treat the July 14 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions.[27]
July 13, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 13, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 13-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 13 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Qualys, ITPro, IndustrialCyber, CybersecurityNews, SecurityWeek, The Hacker News, The Times, The Sun, and related public reporting; newly observed July 12-July 13 items were checker freshness, older or already represented summaries, unrelated Fortinet PSIRT items, blocked/social/video pages, or duplicate recaps already represented by retained sources. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.2. Treat the July 13 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions.[27]
July 12, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 12, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 12-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 12 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Qualys, ITPro, IndustrialCyber, CybersecurityNews, SecurityWeek, The Hacker News, The Times, The Sun, and related public reporting; newly observed July 11-July 12 items were checker freshness, social/video posts, older secondary summaries, blocked pages, unrelated Fortinet PSIRT items, or duplicate recaps already represented by retained sources. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.1. Treat the July 12 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions.[27]
July 11, 2026 8:00 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 11, 2026 8:00 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 11-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 11 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Qualys, ITPro, SecurityWeek, The Hacker News, The Times, The Sun, and related public reporting; newly observed July 10-July 11 items were checker freshness, older secondary summaries, blocked or member-only pages, unrelated Fortinet PSIRT items, or duplicate recaps already represented by retained sources. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v3.0. Treat the July 11 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions.[27]
July 10, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 10, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 10-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar, BleepingComputer, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, Security Affairs, Kevin Beaumont, Diachenko, WaterISAC, Unit 42, Recorded Future, Arctic Wolf, Sophos, SpyCloud, Huntress, Qualys, ITPro, SC Media, SecurityWeek, The Hacker News, The Times, The Sun, and related public reporting. No source-backed content delta was identified. SOCRadar FortiBleed Check remained last updated July 9, 2026 with unchanged headline metrics; newly observed July 9-July 10 items were secondary recaps, university/news-bulletin link collections, older vendor summaries, blocked or member-only pages, social/video posts, unrelated Fortinet PSIRT items, or SEO rewrites already represented by retained sources. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, and Fortinet/CISA remain controlling for official vulnerability-status and hardening language.
July 9, 2026 8:01 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 9, 2026 8:01 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 9-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: indexed public SOCRadar FortiBleed Check content now shows a July 9 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Qualys, ITPro, SecurityWeek, The Hacker News, The Times, The Sun, and related public reporting; newly observed July 8-July 9 items were checker freshness, duplicate recaps, videos/social posts, older summaries, unsupported claims, blocked pages, or SEO rewrites. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.9. Treat the July 9 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions.[27]
July 8, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 8, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 8-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar's FortiBleed Check now shows a July 8 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Dataprise, Picus, Bitdefender, The Hacker News, IndustrialCyber, ITPro, The Times, The Sun, and related public reporting; newly observed July 7-July 8 items were checker freshness, duplicate SOCRadar ransomware-link recaps, UK follow-on reporting already represented by retained sources, older summaries, unsupported claims, blocked pages, or SEO rewrites. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.8. Treat the July 8 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions.[27]
July 7, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 7, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 7-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar's FortiBleed Check now shows a July 7 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Newly retained; published >24h before this run: UK NCSC's June 18 alert directly corroborates Fortinet firewall/VPN-gateway targeting and UK-focused response steps. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Dataprise, Picus, Bitdefender, The Hacker News, The Times, The Sun, and related public reporting; newly observed July 6-July 7 items were duplicate UK syndication, older summaries, unsupported, members-only/TLP-limited, or unsuitable for publication. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Timeline, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.7. Treat the July 7 checker timestamp as live-dataset freshness and continued exposure-check relevance, not a new baseline count of unique devices, victims, or confirmed intrusions; treat NCSC as official UK response guidance, not as a raw victim source.[27] [39]
July 6, 2026 8:55 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 6, 2026 8:55 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 6-Jul-2026 · Added Evidence / Change: Source-backed delta found. Freshly reported (<24h): July 5 UK reporting from The Times and The Sun, with The Sun attributing list details to The Telegraph, says FortiBleed-linked stolen-login activity affected UK Foreign Office and local-government account examples, cites roughly 80,000 Fortinet security-firewall accounts in the reporting cluster, and says NCSC issued Fortinet brute-force alerting. Revisited Fortinet PSIRT, CISA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Dataprise, Picus, Bitdefender, The Hacker News, Cybersecurity Dive, SecurityWeek, RH-ISAC, NCSC-oriented search results, The Times, The Sun, and related public reporting. Duplicate July 2-July 6 SOCRadar/INC/Lynx summaries and SEO rewrites were not retained as additional citations. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Timeline, IOCs / Observables, Real World Examples, Public Victims / Disclosure Matrix, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.6. Treat UK reporting as reported public-sector exposure context and NCSC-alert urgency; do not publish raw account lists, credentials, sensitive dataset rows, or organization-specific impact claims without local or first-party confirmation.[37] [38]
July 5, 2026 5:43 PM ET manual source review
FortiBleed AI Monitoring Agent
Update Time: July 5, 2026 5:43 PM ET manual source review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 5-Jul-2026 · Checked Evidence / Change: User-supplied Recorded Future/Insikt FortiBleed URL checked. The source was already retained as citation 34 and first incorporated in v1.7; no new source was added. Visible language was clarified to preserve behavior-level workflow and infrastructure scoping value while continuing to withhold raw infrastructure, artifacts, victim references, credentials, and acquisition paths. Affected Cards: AI Agent Delta Updates, BLUF, Source Reconciliation, About the Contributors, Source Weighting, Citations, Version Change Log, metadata Action Required: No version increment. Treat Recorded Future as corroboration and deconfliction support, not as a source for publishing raw operational artifacts or organization-specific impact.[34]
July 5, 2026 8:01 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 5, 2026 8:01 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 5-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h); exact update time unavailable: SOCRadar's FortiBleed Check now shows a July 5 update date, says new compromised devices are being added to the attacker database, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT/FortiGuard, CISA/NICCS, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Dataprise, Picus, Bitdefender, The Hacker News, CSA, eSentire, S-RM, and related public reporting; newly observed July 4-July 5 items were duplicative summaries, older than this run, unsupported, or unsuitable for publication. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.5. Treat the July 5 checker timestamp as live-dataset freshness and continued exposure-check relevance, not as a new baseline count of unique devices, victims, or confirmed intrusions.[27]
July 4, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 4, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 4-Jul-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed, Fortinet/FortiGate credential-exposure, FortigateSniffer, SOCRadar, BleepingComputer, Hudson Rock, Fortinet PSIRT/FortiGuard, CISA/NICCS, Security Affairs, Kevin Beaumont, Diachenko, WaterISAC, Unit 42, Arctic Wolf, Sophos, SpyCloud, Recorded Future, Huntress, Dataprise, Picus, Bitdefender, The Hacker News, CSA, eSentire, S-RM, and related public reporting. No source-backed content delta was identified. Newly observed Dataprise July 4 reporting duplicated already represented CISA/Fortinet/SOCRadar framing; older Security Affairs/Mysterium-style marketplace summaries duplicated retained SantaAd/access-broker deconfliction or included sensitive marketplace/victim-detail context unsuitable for publication. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment. Continue daily monitoring; next scheduled run remains daily at 12:00 PM ET, and Fortinet/CISA remain controlling for official vulnerability-status and hardening language.
July 3, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 3, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 3-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Newly retained; exact update time unavailable: SOCRadar's FortiBleed Check now shows a July 2 update date, says new compromised devices are being added, and retains the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. Revisited Fortinet PSIRT, CISA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, FortiGuard PSIRT, Picus, CSA, Huntress, The Hacker News, SecurityWeek, RH-ISAC, Cybersecurity Dive, TechTimes, and related public reporting; newly observed July 2-July 3 articles duplicated SOCRadar's July 2 STRU ransomware-link findings already represented in v2.3, were older than this run, unsupported, or unsuitable for publication. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.4. Treat the July 2 checker timestamp as live-dataset freshness, not as a new baseline victim/device count; keep ransomware-link findings source-caveated to SOCRadar pending the promised whitepaper.[27]
July 2, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 2, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 2-Jul-2026 · Added Evidence / Change: Source-backed delta found. Freshly reported (<24h): SOCRadar STRU published a July 2 update linking FortiBleed infrastructure to INC Ransom and Lynx ransomware operations. New retained findings include 200+ additional operational servers, roughly 11,250 FortiGate portals scanned across 150+ countries, admin-level access confirmed on 409 targets, full domain compromise on 354, at least 12 ransomware deployments, and an organized roughly 20-person operation. Revisited Fortinet PSIRT, CISA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, FortiGuard PSIRT, Picus, CSA, Huntress, and related public reporting; other newly observed items were duplicative summaries, older than this run, already represented, unsupported, or unsuitable for publication. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Timeline, Term Glossary, TTPs, Threat Actor Glossary, Source Reconciliation, Contributor Notes, Real World Examples, Public Victims / Disclosure Matrix, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.3. Treat ransomware-link figures as SOCRadar aggregate findings; do not publish victim lists, operator aliases, raw infrastructure, indicators, credentials, or acquisition paths until a public technical report provides publishable artifacts.[36]
July 1, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: July 1, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 1-Jul-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h): SOCRadar's FortiBleed Check now shows a July 1 update timestamp, says new compromised devices are being added, and retains the same 437K+ targeted devices, 90K+ IPs, 750K+ credentials, and 105M+ records headline metrics. Revisited Fortinet PSIRT, CISA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, FortiGuard PSIRT, CSA, Huntress, and related public reporting; other newly observed items were duplicative summaries, older than this run, already represented, unsupported, or unsuitable for publication. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Contributor Notes, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.2. Treat the July 1 checker timestamp as live-dataset freshness, not as a new baseline victim/device count; continue separating original URL/domain counts from active-operation metrics.[27]
June 30, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: June 30, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 30-Jun-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h): SOCRadar's FortiBleed investigation page shows a June 29 9:00 AM EST update attributing FortiBleed to Lynx / INC and saying a full technical report is forthcoming. Revisited Fortinet PSIRT, CISA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Picus, CybersecurityTribe, and related public reporting; Picus and other newly observed items were duplicative summaries or already represented. Affected Cards: AI Agent Delta Updates, BLUF, Executive Summary, Threat Actor Glossary, Source Reconciliation, Contributor Notes, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.1. Keep SOCRadar's Lynx / INC attribution visibly caveated; do not treat it as universal attribution for every exposure, credential use, victim environment, or downstream incident.[12]
June 29, 2026 8:04 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: June 29, 2026 8:04 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 29-Jun-2026 · Revised Evidence / Change: Source-backed delta found. Freshly reported (<24h): SOCRadar's FortiBleed Check now shows a June 29 update timestamp, retains the same 437K+ targeted devices, 90K+ IPs, 750K+ credentials, and 105M+ records headline metrics, and adds a 59.3M-host active scanning figure. Revisited CybelAngel, Risky Business, Kevin Beaumont, Fortinet PSIRT, CISA, Hudson Rock, BleepingComputer, SOCRadar, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Arctic Wolf, Sophos, SpyCloud, and NCSC-referenced reporting; other items were duplicative, secondary, already represented, or unsuitable for publication. Affected Cards: AI Agent Delta Updates, BLUF, Exposure Snapshot, Source Reconciliation, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v2.0. Preserve baseline URL counts vs active-operation and scanning metrics; do not publish raw victim lists, credentials, operational artifacts, or acquisition paths.[27]
June 28, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: June 28, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 28-Jun-2026 · Checked Evidence / Change: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content delta was identified. Newly observed or revisited items, including Bitdefender, The Hacker News, CSA Singapore, IANS, CISA, Fortinet PSIRT, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Beaumont, and Arctic Wolf, were already represented, duplicative, secondary summaries, or did not change the brief's source-backed conclusions. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment. Continue daily monitoring; keep Fortinet/CISA controlling for official vulnerability status and hardening guidance.
June 27, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: June 27, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 27-Jun-2026 · Added Evidence / Change: Source-backed deltas found. Freshly reported (<24h): SOCRadar's FortiBleed Check now shows a June 27 update timestamp with unchanged 437K+ targeted devices, 90K+ IPs, 750K+ credentials, and 105M+ records. SOCRadar's campaign page adds 80,553 unique devices and 23,406 organizational domains to the active-operation metric vocabulary. Freshness corrected: Unit 42 shows a June 26 publication date; its claims were already represented, so this run corrected metadata rather than adding new Unit 42 findings. Affected Cards: AI Agent Delta Updates, BLUF, Exposure Snapshot, Source Reconciliation, Contributor Notes, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v1.8. Preserve baseline URL count vs current active-operation metrics and do not republish raw campaign artifacts, IPs, hashes, victims, or credentials.[27] [32] [35]
June 26, 2026 8:03 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: June 26, 2026 8:03 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 26-Jun-2026 · Added Evidence / Change: Source-backed deltas found. Freshly reported (<24h): SOCRadar's FortiBleed Check now shows a June 26 update timestamp while retaining the same 437K+ targeted devices, 90K+ IPs, 750K+ credentials, and 105M+ records headline metrics. Newly retained; published >24h before this run: Recorded Future/Insikt adds seller-credibility deconfliction, including a likely credible SantaAd assessment and a separate low-credibility copycat/re-extortion warning. Affected Cards: AI Agent Delta Updates, BLUF, Source Reconciliation, Social Signal, Contributor Notes, Source Weighting, Citations, Version Change Log, metadata, PANDA index timestamps Action Required: Incremented to v1.7. Use the new source to qualify marketplace claims and maintain no-raw-artifact/no-victim-detail publication boundaries.[27] [34]
June 25, 2026 8:02 AM ET agent review
FortiBleed AI Monitoring Agent
Update Time: June 25, 2026 8:02 AM ET agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 25-Jun-2026 · Checked Evidence / Change: AI Monitoring Agent checked Fortinet PSIRT, CISA, SOCRadar, BleepingComputer, Hudson Rock, Diachenko/Kevin Beaumont reporting, Field Effect, Bitdefender, The Hacker News, SC Media, ZenoX, Security Affairs, WaterISAC, and related public sources. No source-backed content change was identified; newer items were duplicates, summaries of already retained SOCRadar/Arctic Wolf/SpyCloud evidence, or unsuitable for publication because they exposed sensitive operational artifacts. Affected Cards: AI Agent Delta Updates, Version Change Log, metadata, PANDA index timestamps Action Required: No version increment. Continue daily monitoring and keep official Fortinet/CISA language controlling for vulnerability-status and hardening claims.
June 24, 2026 agent review
FortiBleed AI Monitoring Agent
Update Time: June 24, 2026 agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 24-Jun-2026 · Added Evidence / Change: Arctic Wolf reverse-engineered a recovered CyberStrike Harvester binary and tied it to a FortiBleed workflow involving credential stuffing, password spraying, configuration harvesting, offline cracking, post-authentication capture processing, AD/SMB access tooling, credential cleaners, and Hashcat/Hashtopolis infrastructure. SANS adds perimeter-device playbook guidance. Unit 42 publication metadata is corrected in the June 27 monitoring row. Affected Cards: BLUF, Executive Summary, TTPs, Term Glossary, IOCs, Threat Actor Glossary, Talking Points, Source Reconciliation, Source Weighting, Citations Action Required: Add CyberStrike Harvester/toolchain hunt pivots while withholding raw hashes, IPs, victim artifacts, credentials, acquisition paths, and sensitive dataset excerpts.[31] [33]
June 23, 2026 agent review
FortiBleed AI Monitoring Agent
Update Time: June 23, 2026 agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 23-Jun-2026 · Added Evidence / Change: Sophos published an official advisory saying the same threat actors targeted internet-exposed Sophos Firewall appliances via user-level credential brute-forcing/stuffing, especially where MFA was not enforced or enrolled for Admin, User, or VPN portals; Sophos had not observed Sophos Firewall compromise or vulnerability exploitation in reviewed telemetry. Affected Cards: BLUF, Executive Summary, Decision Ready Actions, Exploitable Technology Risks, Source Reconciliation, Source Weighting, Additional Products, Citations Action Required: Treat Sophos Firewall cases as adjacent credential-stuffing/edge-access scoping unless local telemetry proves successful access, session persistence, data impact, or a distinct vulnerability path.[30]
June 23, 2026 agent review
FortiBleed AI Monitoring Agent
Update Time: June 23, 2026 agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 23-Jun-2026 · Added Evidence / Change: SpyCloud Labs reports that the FortiBleed material is part of a broader multi-server initial-access-broker operation with brute-force, operator-workstation, and cracking roles, non-Fortinet scanning, AI-assisted tooling, and marketplace signal around SantaAd. Affected Cards: BLUF, Executive Summary, Threat Actor Glossary, TTPs, IOCs, Real World Examples, Source Reconciliation, Source Weighting, Citations Action Required: Expand hunting to adjacent edge-device, MSSQL, AI-assisted tooling, session-replay, and access-broker tradecraft while withholding sensitive victim and infrastructure details.[29]
June 23, 2026 agent review
FortiBleed AI Monitoring Agent
Update Time: June 23, 2026 agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 23-Jun-2026 · Revised Evidence / Change: The technical framing now explicitly separates initial access from post-compromise sniffing: FortigateSniffer is most useful after the attacker already has management access, because FortiGate sits at the network edge and can observe credential-bearing traffic. Affected Cards: BLUF, Executive Summary, TTPs, IOCs, MITRE Mapping, Talking Points Action Required: Ask scopers to preserve FortiGate admin/SSH logs, diagnostic command evidence, PCAP/export artifacts, and protocol-specific authentication windows.[25] [26]
June 23, 2026 agent review
FortiBleed AI Monitoring Agent
Update Time: June 23, 2026 agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 22-Jun-2026 · Added Evidence / Change: New SOCRadar and BleepingComputer reporting reframes FortiBleed from only a credential-exposure dataset into an active credential-harvesting operation using FortigateSniffer, SNIFTRAN/PCAP parsing, automation infrastructure, and credential cracking workflows. Affected Cards: BLUF, Executive Summary, TTPs, IOCs, MITRE Mapping, Source Reconciliation Action Required: Add FortigateSniffer and packet-sniffing evidence to hunting and scoping.[25] [26] [28]
June 23, 2026 agent review
FortiBleed AI Monitoring Agent
Update Time: June 23, 2026 agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 22-Jun-2026 · Revised Evidence / Change: SOCRadar's updated materials cite 430,000+ targeted devices, 90,000+ IPs, 750,000+ credentials, and 105M+ records, while the original brief retained 73,932 firewall/SSL VPN URLs and roughly 21,632 affected domains. Affected Cards: Exposure Snapshot, Executive Summary, Source Reconciliation, Citations Action Required: Keep baseline URL count and updated active-operation scale as separate metrics.[4] [6] [25] [27]
June 23, 2026 agent review
FortiBleed AI Monitoring Agent
Update Time: June 23, 2026 agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 22-Jun-2026 · Added Evidence / Change: SOCRadar describes more than 1,000 compromised victims across 120 countries, with outsized SMB exposure and at least one NATO-aligned defense-contractor case, but public reporting still does not provide a publishable victim list for broad reuse. Affected Cards: Real World Examples, Talking Points, Source Reconciliation Action Required: Use victimology for scoping priority, not public attribution.[25] [27] [28]
June 23, 2026 agent review
FortiBleed AI Monitoring Agent
Update Time: June 23, 2026 agent review Agent / Monitor: FortiBleed AI Monitoring Agent Delta Type: 22-Jun-2026 · Qualified Evidence / Change: The brief should no longer imply the public story is only a static leak list. It should also avoid upgrading every exposure match into confirmed compromise, because Fortinet's no-new-vulnerability position and CISA's hardening guidance still require local validation. Affected Cards: Executive Summary, BLUF, Source Reconciliation Action Required: Preserve the distinction between targeted, exposed, credential-valid, successfully accessed, and impacted.[13] [14] [25] [26]
Brief ID
PANDA-FTIB-FORTIBLEED-2026-001
Current Brief Version
v4.5
Initial Publish Date
19-Jun-2026
First AI Agent Update Run
22-Jun-2026
AI Monitoring Updates Applied
74x
Next Scheduled Monitor
Daily at 12:00 PM ET for 6 months
Why It Matters
Edge-access credential exposure
Fortinet/FortiGate SSL VPN and firewall credentials protect network entry points; exposed credentials can create direct access risk without requiring a new exploit.
Theme: Edge-access credential exposure Why It Matters: Fortinet/FortiGate SSL VPN and firewall credentials protect network entry points; exposed credentials can create direct access risk without requiring a new exploit. Defender Implication: Treat this as an identity and access emergency for Fortinet VPN/admin accounts.[4] [5] [13] [14]
Scale and scoping complexity
Reporting cites 73,932 firewall or SSL VPN URLs and roughly 21,632 affected domains, but URL counts do not necessarily equal unique devices.
Theme: Scale and scoping complexity Why It Matters: Reporting cites 73,932 firewall or SSL VPN URLs and roughly 21,632 affected domains, but URL counts do not necessarily equal unique devices. Defender Implication: Map URLs and domains to owned assets before declaring impact.[3] [4] [6] [16]
Plaintext password risk
Reports say exposed records include usernames, email addresses, and plaintext passwords in many cases.
Theme: Plaintext password risk Why It Matters: Reports say exposed records include usernames, email addresses, and plaintext passwords in many cases. Defender Implication: Rotate Fortinet passwords and investigate reuse across remote-access and admin systems.[3] [4] [5] [16]
No single patch resolution
Fortinet states this activity is not a new Fortinet vulnerability or recent advisory; CISA guidance focuses on credential/session hardening.
Theme: No single patch resolution Why It Matters: Fortinet states this activity is not a new Fortinet vulnerability or recent advisory; CISA guidance focuses on credential/session hardening. Defender Implication: Pair patch governance with credential rotation, MFA, log review, and interface restriction.[13] [14]
Persistent-access concern
CSO Online, SOCRadar, and Security Affairs reporting describe persistent-access concerns, operational infrastructure, stolen passwords, tools, automation infrastructure, victim-list context, and configuration-export uncertainty, but not a reliable public count of successful password use or firewall changes.
Theme: Persistent-access concern Why It Matters: CSO Online, SOCRadar, and Security Affairs reporting describe persistent-access concerns, operational infrastructure, stolen passwords, tools, automation infrastructure, victim-list context, and configuration-export uncertainty, but not a reliable public count of successful password use or firewall changes. Defender Implication: Review successful VPN and firewall-admin logins, admin account changes, policy changes, and unusual sessions.[8] [12] [16]
Active packet-capture operation
22-Jun-2026 · Added The SOCRadar/BleepingComputer delta describes FortigateSniffer using legitimate FortiOS diagnostic packet capture to harvest credentials, meaning this is not limited to checking whether a password appeared in a static leak.
Theme: Active packet-capture operation Why It Matters: 22-Jun-2026 · Added The SOCRadar/BleepingComputer delta describes FortigateSniffer using legitimate FortiOS diagnostic packet capture to harvest credentials, meaning this is not limited to checking whether a password appeared in a static leak. Defender Implication: Preserve Fortinet admin logs and investigate diagnostic command use, PCAP exports, captured protocols, credential cracking, and replay activity.[25] [26] [28]
2-Jul-2026 · Added Ransomware precursor risk
SOCRadar now reports a direct connection between FortiBleed infrastructure and INC Ransom/Lynx negotiation panels, plus at least 12 ransomware deployments stemming from FortiBleed-derived access.
Theme: 2-Jul-2026 · Added Ransomware precursor risk Why It Matters: SOCRadar now reports a direct connection between FortiBleed infrastructure and INC Ransom/Lynx negotiation panels, plus at least 12 ransomware deployments stemming from FortiBleed-derived access. Defender Implication: For confirmed FortiBleed exposure, escalate beyond credential rotation into domain-controller, ransomware-preparation, lateral-movement, and recovery-readiness review.[36]
Timeline
June 17, 2026
Diachenko and Hudson Rock public materials identify or amplify the FortiBleed dataset and lookup workflow.
Date / Period: June 17, 2026 Event: Diachenko and Hudson Rock public materials identify or amplify the FortiBleed dataset and lookup workflow. Source-Backed Meaning: Establishes the public-disclosure window for the reported dataset. Caveat: Use the primary posts/pages for exact wording and screenshots; secondary reporting still helps cross-check scale claims.[9] [10] [11]
June 17, 2026
Reporting describes 73,932 Fortinet firewall or SSL VPN URLs and roughly 21,632 affected domains.
Date / Period: June 17, 2026 Event: Reporting describes 73,932 Fortinet firewall or SSL VPN URLs and roughly 21,632 affected domains. Source-Backed Meaning: Provides the core scale figures defenders can use for risk framing and scoping. Caveat: Validate against Hudson Rock methodology and any organization-specific lookup result before declaring impact.[9] [10] [16]
June 18, 2026
BleepingComputer reports the leak exposed what appears to be Fortinet/FortiGate VPN credentials for 73,932 firewall URLs.
Date / Period: June 18, 2026 Event: BleepingComputer reports the leak exposed what appears to be Fortinet/FortiGate VPN credentials for 73,932 firewall URLs. Source-Backed Meaning: Corroborates the central public claim and exposed-data categories. Caveat: Appearance-based reporting does not prove all credentials are current or working.[4]
June 18, 2026
CSO Online reports researcher warnings about persistent access and an operational server containing stolen FortiGate passwords, tools, automation infrastructure, and a victim list.
Date / Period: June 18, 2026 Event: CSO Online reports researcher warnings about persistent access and an operational server containing stolen FortiGate passwords, tools, automation infrastructure, and a victim list. Source-Backed Meaning: Adds operational-risk context beyond a static credential dataset. Caveat: SOCRadar now provides a primary source to compare against the secondary CSO Online summary.[8] [12]
June 18, 2026
CISA urges Fortinet customers to harden devices after reports of credential exposure.
Date / Period: June 18, 2026 Event: CISA urges Fortinet customers to harden devices after reports of credential exposure. Source-Backed Meaning: Adds authoritative public-sector response guidance for sessions, passwords, MFA, and log review. Caveat: CISA guidance confirms urgency without proving successful compromise at every listed organization.[14]
7-Jul-2026 · Added June 18, 2026
UK NCSC publishes official advice following global targeting of Fortinet firewalls and VPN gateways.
Date / Period: 7-Jul-2026 · Added June 18, 2026 Event: UK NCSC publishes official advice following global targeting of Fortinet firewalls and VPN gateways. Source-Backed Meaning: Adds official UK guidance for checker validation, IoC review, isolation/factory-reset escalation, shared-credential scoping, management-interface hardening, MFA, and PBKDF2 enforcement. Caveat: Newly retained on July 7, 2026; published more than 24 hours before this run and used as official response guidance, not as a raw victim source.[39]
26-Aug-2026 · Added June 18, 2026
Canada's Cyber Centre publishes alert AL26-014 after becoming aware of open-source FortiBleed reporting on June 17, 2026.
Date / Period: 26-Aug-2026 · Added June 18, 2026 Event: Canada's Cyber Centre publishes alert AL26-014 after becoming aware of open-source FortiBleed reporting on June 17, 2026. Source-Backed Meaning: Adds official Canadian government guidance for Fortinet account review, suspicious-account removal, management-interface restriction, session termination, password reset, MFA, firmware review, internet-gateway defense, privilege-management, and reporting matching activity. Caveat: Newly retained on August 26, 2026; published more than 24 hours before this run and used as official Canadian response guidance, not as a raw victim source, credential source, compromise count, or new-CVE finding.[45]
June 19, 2026
Fortinet publishes its analysis of the reported credential compromise.
Date / Period: June 19, 2026 Event: Fortinet publishes its analysis of the reported credential compromise. Source-Backed Meaning: Adds official vendor position: not a new Fortinet vulnerability and not related to a recent incident or advisory. Caveat: This narrows the patch/CVE framing but does not remove the need for credential and session response.[13]
23-Jun-2026 · Added June 19, 2026
SpyCloud Labs publishes infrastructure analysis describing multi-server campaign roles, AI-assisted tooling, broader Synology/Sophos/MSSQL targeting, IAB-style monetization, and SantaAd forum signal.
Date / Period: 23-Jun-2026 · Added June 19, 2026 Event: SpyCloud Labs publishes infrastructure analysis describing multi-server campaign roles, AI-assisted tooling, broader Synology/Sophos/MSSQL targeting, IAB-style monetization, and SantaAd forum signal. Source-Backed Meaning: Adds independent access-broker and infrastructure context beyond Fortinet-only exposure. Caveat: Use as scoping and tradecraft evidence; do not republish redacted infrastructure, marketplace, victim, or sensitive exfiltration details.[29]
22-Jun-2026 · Added June 22, 2026
SOCRadar STRU publishes a detailed FortiBleed update describing FortigateSniffer, operation servers, harvest cycles, protocol coverage, and expanded targeting metrics.
Date / Period: 22-Jun-2026 · Added June 22, 2026 Event: SOCRadar STRU publishes a detailed FortiBleed update describing FortigateSniffer, operation servers, harvest cycles, protocol coverage, and expanded targeting metrics. Source-Backed Meaning: Turns the public narrative from only a leak-list event into an active-operation and tooling story. Caveat: Keep SOCRadar's 59.3M scanned-host, 430K+ targeted-device, 80,553 unique-device, 23,406 organizational-domain, and 105M+ record metrics separate from the original 73,932 URL dataset.[25] [27] [35]
22-Jun-2026 · Added June 22, 2026
BleepingComputer reports on SOCRadar's new FortigateSniffer findings.
Date / Period: 22-Jun-2026 · Added June 22, 2026 Event: BleepingComputer reports on SOCRadar's new FortigateSniffer findings. Source-Backed Meaning: Provides mainstream technical corroboration of the packet-capture, SNIFTRAN, PCAP-analysis, and credential-cracking workflow. Caveat: BleepingComputer summarizes the SOCRadar findings; use SOCRadar for primary technical detail where available.[25] [26]
7-Aug-2026 · Added June 25, 2026
CybelAngel REACT publishes a public flash-report summary with planted Fortinet-service-like administrator account names.
Date / Period: 7-Aug-2026 · Added June 25, 2026 Event: CybelAngel REACT publishes a public flash-report summary with planted Fortinet-service-like administrator account names. Source-Backed Meaning: Adds concrete local persistence-review pivots for organizations that receive a FortiBleed exposure match or see suspicious FortiGate admin activity. Caveat: Newly retained on August 7, 2026; published more than 24 hours before this run. Use the account names as hunt terms, not as proof of compromise without local telemetry.[42]
13-Aug-2026 · Added June 30, 2026
Roche Diagnostics publishes a first-party response to FortiBleed credential exposure.
Date / Period: 13-Aug-2026 · Added June 30, 2026 Event: Roche Diagnostics publishes a first-party response to FortiBleed credential exposure. Source-Backed Meaning: Adds a public example of named-list deconfliction: Roche identified two Roche-associated FortiGate devices in the dataset but found no evidence of impact to Roche customer Laboratory Networks. Caveat: Newly retained on August 13, 2026; published more than 24 hours before this run. Use as first-party customer-impact boundary context, not as raw exposure, credential-validity, or broader compromise proof.[43]
2-Jul-2026 · Added July 2, 2026
SOCRadar STRU publishes a new update linking FortiBleed infrastructure to INC Ransom and Lynx ransomware operations.
Date / Period: 2-Jul-2026 · Added July 2, 2026 Event: SOCRadar STRU publishes a new update linking FortiBleed infrastructure to INC Ransom and Lynx ransomware operations. Source-Backed Meaning: Adds source-backed ransomware-impact and operator-structure context to the active-operation layer. Caveat: SOCRadar's public Volume II landing page now summarizes operator, hierarchy, AI-assisted-operation, targeting, ATT&CK, and IoC-availability themes, but this public brief should still publish only aggregate, source-backed findings and keep raw indicators, operator artifacts, infrastructure, victim rows, credentials, and victim-specific impact dependent on local telemetry.[36] [40]
6-Jul-2026 · Added July 5, 2026
UK press reporting describes Foreign Office and local-government account examples in a FortiBleed-linked stolen-login cluster and references NCSC Fortinet brute-force alerting.
Date / Period: 6-Jul-2026 · Added July 5, 2026 Event: UK press reporting describes Foreign Office and local-government account examples in a FortiBleed-linked stolen-login cluster and references NCSC Fortinet brute-force alerting. Source-Backed Meaning: Adds a freshly reported public-sector exposure example and reinforces that exposed credentials should be handled as urgent government and critical-infrastructure scoping leads. Caveat: Treat as UK media reporting and alert-context corroboration; do not publish raw account details, credentials, or organization-specific impact claims without first-party or local telemetry confirmation.[37] [38]
Incident Response Playbook Ideas
Scoping
Inventory all internet-facing FortiGate SSL VPN endpoints, Fortinet firewall URLs, and public Fortinet administrative interfaces. Map them to owned domains and business owners.
Phase: Scoping Playbook Idea: Inventory all internet-facing FortiGate SSL VPN endpoints, Fortinet firewall URLs, and public Fortinet administrative interfaces. Map them to owned domains and business owners. Evidence Basis: Reporting centers on firewall and SSL VPN URLs, affected domains, and internet-facing Fortinet devices. What To Avoid: Do not assume the public count maps cleanly to unique devices in your environment.[3] [4] [5] [6] [16]
Credential containment
Terminate active SSL VPN and administrative sessions, then rotate Fortinet VPN/admin passwords and any reused passwords tied to exposed usernames or email addresses.
Phase: Credential containment Playbook Idea: Terminate active SSL VPN and administrative sessions, then rotate Fortinet VPN/admin passwords and any reused passwords tied to exposed usernames or email addresses. Evidence Basis: CISA calls for terminating SSL VPN and administrative sessions and resetting VPN/admin passwords; reporting describes usernames, emails, and plaintext passwords in many cases. What To Avoid: Do not wait for proof that every credential is still valid before rotating high-risk remote-access credentials.[4] [5] [14]
Access control
Enforce MFA on FortiGate SSL VPN and administrative access and restrict management interfaces from the public internet where feasible.
Phase: Access control Playbook Idea: Enforce MFA on FortiGate SSL VPN and administrative access and restrict management interfaces from the public internet where feasible. Evidence Basis: CISA recommends phishing-resistant MFA and Fortinet frames weak password hygiene and lack of MFA as key exposure conditions. What To Avoid: Do not rely on patching alone, because the public record does not establish a single FortiBleed CVE.[13] [14]
Investigation
Review authentication logs for successful and failed Fortinet VPN/admin logins, especially unfamiliar sources, unusual geographies, exposed accounts, and high-volume attempts.
Phase: Investigation Playbook Idea: Review authentication logs for successful and failed Fortinet VPN/admin logins, especially unfamiliar sources, unusual geographies, exposed accounts, and high-volume attempts. Evidence Basis: CISA calls for log review, while public reporting describes potentially valid, tested, stolen, or cracked FortiGate passwords and persistent-access risk. What To Avoid: Do not publish or act on unsourced IOCs; no IPs, hashes, domains, or signatures are retained.[4] [6] [8] [14] [16]
Packet-capture review
22-Jun-2026 · Added Check whether FortiGate diagnostic packet capture was invoked unexpectedly and whether PCAP exports, SSH/admin sessions, or protocol-level credential harvesting may have occurred.
Phase: Packet-capture review Playbook Idea: 22-Jun-2026 · Added Check whether FortiGate diagnostic packet capture was invoked unexpectedly and whether PCAP exports, SSH/admin sessions, or protocol-level credential harvesting may have occurred. Evidence Basis: SOCRadar and BleepingComputer describe FortigateSniffer using FortiOS diagnostic packet-sniffing functionality and PCAP/SNIFTRAN processing to extract credentials and hashes. What To Avoid: Do not treat absence of malware files as absence of activity; the reported mechanism can abuse legitimate diagnostic functionality.[25] [26]
Persistence and change review
7-Aug-2026 · Revised Review admin account creation, privilege changes, policy changes, configuration changes, unusual long-lived VPN sessions, and planted Fortinet-service-like account names after any exposure match.
Phase: Persistence and change review Playbook Idea: 7-Aug-2026 · Revised Review admin account creation, privilege changes, policy changes, configuration changes, unusual long-lived VPN sessions, and planted Fortinet-service-like account names after any exposure match. Evidence Basis: CSO Online reports an operational server with stolen passwords, tools, automation infrastructure, and a victim list. Fortinet says to review for unrecognized accounts; CybelAngel adds concrete planted-account name examples. What To Avoid: Do not infer a named actor or fixed attack chain from the current public record.[8] [13] [42]
Access-broker infrastructure review
23-Jun-2026 · Added For confirmed exposure, expand review beyond the FortiGate appliance to session replay, AD/LDAP/Kerberos/NTLM collection, password-cracking workflows, MSSQL access, and adjacent edge-device targeting.
Phase: Access-broker infrastructure review Playbook Idea: 23-Jun-2026 · Added For confirmed exposure, expand review beyond the FortiGate appliance to session replay, AD/LDAP/Kerberos/NTLM collection, password-cracking workflows, MSSQL access, and adjacent edge-device targeting. Evidence Basis: SpyCloud describes a broader multi-server IAB-style operation with brute-force, operator, and cracking infrastructure, plus targeting of Synology, Sophos, and MSSQL in addition to Fortinet. What To Avoid: Do not treat SpyCloud's redacted server, forum, or victim details as public blocklist data.[29]
Term Glossary
FortiBleed
Public name used in reporting for a Fortinet/FortiGate credential-exposure or credential-compromise dataset.
Term: FortiBleed Definition: Public name used in reporting for a Fortinet/FortiGate credential-exposure or credential-compromise dataset. Why It Matters Here: Frames the event as a credential and access problem, not as a confirmed new Fortinet vulnerability.[3] [5] [6]
FortiGate
Fortinet firewall product family referenced in reporting as tied to firewall URLs, SSL VPN access, and administrative interfaces.
Term: FortiGate Definition: Fortinet firewall product family referenced in reporting as tied to firewall URLs, SSL VPN access, and administrative interfaces. Why It Matters Here: These devices often sit at the network edge and can provide high-value access if credentials are exposed.[3] [4] [5] [6] [16]
22-Jun-2026 · Added FortigateSniffer
Name used in SOCRadar/BleepingComputer reporting for a custom tool or workflow tied to FortiGate packet capture and credential extraction.
Term: 22-Jun-2026 · Added FortigateSniffer Definition: Name used in SOCRadar/BleepingComputer reporting for a custom tool or workflow tied to FortiGate packet capture and credential extraction. Why It Matters Here: It expands investigation from leaked credentials to possible diagnostic packet-capture abuse and multi-protocol credential harvesting.[25] [26] [28]
24-Jun-2026 · Added CyberStrike Harvester
Arctic Wolf's name for a recovered binary it reverse-engineered and connected to credential stuffing, spraying, configuration harvesting, offline cracking, post-authentication capture processing, and AD/SMB follow-on tooling.
Term: 24-Jun-2026 · Added CyberStrike Harvester Definition: Arctic Wolf's name for a recovered binary it reverse-engineered and connected to credential stuffing, spraying, configuration harvesting, offline cracking, post-authentication capture processing, and AD/SMB follow-on tooling. Why It Matters Here: Adds a concrete recovered-tooling pivot for detection engineering and forensic scoping while still avoiding publication of raw victim artifacts, credentials, hashes, or infrastructure.[31]
23-Jun-2026 · Revised FortiOS diagnostic packet capture
FortiGate includes legitimate troubleshooting functionality for packet capture; newer reporting says FortigateSniffer abused that built-in capability after access, rather than requiring a separate malware implant for sniffing.
Term: 23-Jun-2026 · Revised FortiOS diagnostic packet capture Definition: FortiGate includes legitimate troubleshooting functionality for packet capture; newer reporting says FortigateSniffer abused that built-in capability after access, rather than requiring a separate malware implant for sniffing. Why It Matters Here: This answers a key scoping question: if an attacker had admin or SSH-level access, they could turn the firewall's normal diagnostic tooling into a credential-harvesting sensor.[25] [26]
23-Jun-2026 · Revised Self-feeding harvesting loop
A post-compromise pattern where one accessed FortiGate device is used to observe additional authentication traffic, extract credentials or hashes, crack or replay them, and widen the next round of access attempts.
Term: 23-Jun-2026 · Revised Self-feeding harvesting loop Definition: A post-compromise pattern where one accessed FortiGate device is used to observe additional authentication traffic, extract credentials or hashes, crack or replay them, and widen the next round of access attempts. Why It Matters Here: Explains why sniffing matters even after initial access: it can expand the credential set and create follow-on intrusion opportunities.[25] [26] [28]
22-Jun-2026 · Added Operation server
Attacker-side infrastructure described in SOCRadar reporting as supporting the FortiBleed harvesting operation; this should not be read as a victim count or a count of unique operators.
Term: 22-Jun-2026 · Added Operation server Definition: Attacker-side infrastructure described in SOCRadar reporting as supporting the FortiBleed harvesting operation; this should not be read as a victim count or a count of unique operators. Why It Matters Here: Useful for understanding that the newer reporting describes an operating infrastructure layer, not only a pasted credential list.[25] [28]
23-Jun-2026 · Added Initial access broker operation
A financially motivated model in which operators obtain or validate access and package it for downstream use or sale.
Term: 23-Jun-2026 · Added Initial access broker operation Definition: A financially motivated model in which operators obtain or validate access and package it for downstream use or sale. Why It Matters Here: SpyCloud and SOCRadar both frame the broader activity as IAB-style, but this remains an analytic role assessment rather than proof of every downstream buyer or intrusion.[25] [29]
23-Jun-2026 · Added AI-assisted operator tooling
SpyCloud's reporting that operators used an AI code editor and AI-powered offensive framework while building or running custom tooling.
Term: 23-Jun-2026 · Added AI-assisted operator tooling Definition: SpyCloud's reporting that operators used an AI code editor and AI-powered offensive framework while building or running custom tooling. Why It Matters Here: This widens tradecraft review to operator workstations, automation, generated scripts, and tooling artifacts; it should not be used to claim the FortiBleed exposure was caused by AI.[29]
22-Jun-2026 · Added Harvest cycle
A reported credential-collection run, pipeline, or activity cycle used by SOCRadar to describe repeated harvesting activity.
Term: 22-Jun-2026 · Added Harvest cycle Definition: A reported credential-collection run, pipeline, or activity cycle used by SOCRadar to describe repeated harvesting activity. Why It Matters Here: Do not equate harvest cycles with victims, devices, or successful intrusions; use the term only as an operation-tempo signal.[25] [27] [28]
22-Jun-2026 · Added Credential harvesting across 24 protocols
SOCRadar's reporting that the operation collected credential-bearing traffic across 24 authentication protocols rather than only Fortinet web/VPN login records.
Term: 22-Jun-2026 · Added Credential harvesting across 24 protocols Definition: SOCRadar's reporting that the operation collected credential-bearing traffic across 24 authentication protocols rather than only Fortinet web/VPN login records. Why It Matters Here: Broadens hunting from FortiGate credential lists to protocol traffic windows, packet captures, and downstream cracking or replay workflows.[25] [26] [28]
2-Jul-2026 · Added FortiBleed-derived access
SOCRadar's term-framing for access it says stemmed from the FortiBleed credential-harvesting operation and fed downstream ransomware activity.
Term: 2-Jul-2026 · Added FortiBleed-derived access Definition: SOCRadar's term-framing for access it says stemmed from the FortiBleed credential-harvesting operation and fed downstream ransomware activity. Why It Matters Here: Use it to escalate confirmed exposure into ransomware-prevention scoping, while keeping aggregate SOCRadar findings separate from organization-specific proof.[36]
2-Jul-2026 · Added Ransomware negotiation panel
An attacker-side interface used to manage victim negotiations; SOCRadar reports a FortiBleed-linked operator was active in both INC Ransom and Lynx panels.
Term: 2-Jul-2026 · Added Ransomware negotiation panel Definition: An attacker-side interface used to manage victim negotiations; SOCRadar reports a FortiBleed-linked operator was active in both INC Ransom and Lynx panels. Why It Matters Here: Supports SOCRadar's ransomware-link assessment, but the brief does not republish operator aliases, panel artifacts, or victim details.[36]
22-Jun-2026 · Added PCAP / SNIFTRAN
Packet-capture data and parser workflow referenced in newer reporting as part of credential extraction from captured traffic.
Term: 22-Jun-2026 · Added PCAP / SNIFTRAN Definition: Packet-capture data and parser workflow referenced in newer reporting as part of credential extraction from captured traffic. Why It Matters Here: Scopers should preserve and review admin activity, packet-capture exports, captured protocols, and downstream cracking/replay evidence.[25] [26]
SSL VPN
Remote-access VPN capability referenced in reporting as part of the affected Fortinet/FortiGate access surface.
Term: SSL VPN Definition: Remote-access VPN capability referenced in reporting as part of the affected Fortinet/FortiGate access surface. Why It Matters Here: Exposed SSL VPN credentials may allow unauthorized remote access if still valid and not protected by MFA.[3] [5]
Firewall URL
The unit most consistently cited in public reporting for the 73,932 figure.
Term: Firewall URL Definition: The unit most consistently cited in public reporting for the 73,932 figure. Why It Matters Here: A URL is not necessarily a unique physical device, so defenders should map URLs to actual assets.[3] [4] [6]
Plaintext Password
A password stored or exposed in readable form rather than only as a hash.
Term: Plaintext Password Definition: A password stored or exposed in readable form rather than only as a hash. Why It Matters Here: Plaintext exposure raises immediate risk of direct login attempts and password reuse across other services.[3] [4] [5] [16]
TTPs
23-Jun-2026 · Revised Access precedes sniffing
T1078
TTP: 23-Jun-2026 · Revised Access precedes sniffing MITRE ATT&CK: T1078 Tactic: Initial Access / Persistence Source-Backed Detail: The sniffer workflow should not be read as the confirmed initial entry method. Public reporting supports a sequence where exposed/reused/cracked credentials or other access paths can provide management access first; diagnostic packet capture then becomes a post-compromise harvesting method. Caveat: The retained public record does not prove one universal initial-access path for every victim.[13] [25] [26]
Open source22-Jun-2026 · Added FortigateSniffer packet capture and credential harvesting
T1040
TTP: 22-Jun-2026 · Added FortigateSniffer packet capture and credential harvesting MITRE ATT&CK: T1040 Tactic: Credential Access Source-Backed Detail: SOCRadar and BleepingComputer describe a custom FortigateSniffer workflow that uses FortiOS packet-capture functionality, parses PCAP traffic, extracts credentials across multiple protocols, and supports cracking/replay activity. Caveat: Do not publish recovered credentials or raw packet-capture artifacts; validate command use and captured protocols in local Fortinet telemetry.[25] [26] [28]
Open source2-Jul-2026 · Added FortiBleed-derived ransomware access
T1078 / T1486
TTP: 2-Jul-2026 · Added FortiBleed-derived ransomware access MITRE ATT&CK: T1078 / T1486 Tactic: Initial Access / Impact Source-Backed Detail: SOCRadar reports FortiBleed-derived access led to admin-level access on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments tied to INC Ransom and Lynx operations. Caveat: Use this as aggregate ransomware-risk evidence; do not infer ransomware impact for any organization without local domain, endpoint, identity, and backup telemetry.[36]
Open source24-Jun-2026 · Added CyberStrike Harvester and post-authentication toolchain
T1110 / T1003
TTP: 24-Jun-2026 · Added CyberStrike Harvester and post-authentication toolchain MITRE ATT&CK: T1110 / T1003 Tactic: Credential Access / Discovery Source-Backed Detail: Arctic Wolf reports reverse-engineering a recovered CyberStrike Harvester binary and tying it to a workflow with credential stuffing, password spraying, configuration harvesting, offline cracking, post-authentication capture processing, AD/SMB tooling, credential cleaners, and cracking infrastructure. Caveat: Use source-reported tool names and behaviors for hunting; do not republish raw recovered artifacts or sensitive infrastructure.[31]
Open source23-Jun-2026 · Added Access-broker automation and AI-assisted tooling
T1583 / T1584
TTP: 23-Jun-2026 · Added Access-broker automation and AI-assisted tooling MITRE ATT&CK: T1583 / T1584 Tactic: Resource Development / Credential Access Source-Backed Detail: SpyCloud describes a broader operator workflow with brute-force, operator-workstation, and cracking roles; tooling included off-the-shelf offensive utilities, custom scripts, an AI code editor, and an AI-powered penetration-testing framework. Caveat: Use for scoping operator tradecraft and detection coverage; it does not prove AI generated every tool or caused the exposure.[29]
Open sourceUse or attempted use of exposed credentials
T1078
TTP: Use or attempted use of exposed credentials MITRE ATT&CK: T1078 Tactic: Initial Access / Persistence Source-Backed Detail: Public reporting and the CISA hardening alert describe compromised or exposed Fortinet credentials that could support VPN or firewall administrative access. Caveat: Reporting does not prove every listed credential is current or successful.[4] [6] [14] [16]
Open sourceCredential validation or password attack activity
T1110
TTP: Credential validation or password attack activity MITRE ATT&CK: T1110 Tactic: Credential Access Source-Backed Detail: Fortinet references brute-force techniques and credential reuse; Hackread, CSO Online, and Security Affairs report stolen, tested, potentially working, or cracked FortiGate passwords. Caveat: Validation methodology and working-credential counts are not retained.[6] [8] [13] [16]
Open sourceRemote access through exposed edge services
T1133
TTP: Remote access through exposed edge services MITRE ATT&CK: T1133 Tactic: Initial Access / Persistence Source-Backed Detail: FortiGate SSL VPN and exposed Fortinet firewall-administration interfaces are the relevant external access paths for scoping. Caveat: No retained source provides environment-specific log queries or interface configuration baselines.[3] [5]
Open sourceAccount or permission changes after access
T1098
TTP: Account or permission changes after access MITRE ATT&CK: T1098 Tactic: Persistence / Privilege Escalation Source-Backed Detail: Persistent-access concern makes admin account creation, privilege changes, policy changes, and configuration changes priority review areas. Caveat: The retained record does not prove this happened at every listed organization.[8]
Open sourceCommon Questions Q&A
Why would the attacker sniff traffic after they already got in?
Because a FortiGate device sits at the network edge and can see VPN, admin, directory, and application authentication traffic that may cross it. New reporting says the operation used FortigateSniffer to turn compromised devices into credential-harvesting sensors, feeding additional credentials or hashes into parsing, cracking, and replay workflows.
Question: Why would the attacker sniff traffic after they already got in? Source-Backed Answer: Because a FortiGate device sits at the network edge and can see VPN, admin, directory, and application authentication traffic that may cross it. New reporting says the operation used FortigateSniffer to turn compromised devices into credential-harvesting sensors, feeding additional credentials or hashes into parsing, cracking, and replay workflows. What To Collect: Preserve FortiGate admin logs, SSH/admin-session records, packet-capture artifacts, and authentication windows for VPN, LDAP/RADIUS/AD, Kerberos/NTLM, email, database, and other exposed protocols.[25] [26] [28]
Is sniffing how the attacker initially got in?
Not necessarily. Fortinet's public framing points to credential reuse and brute-force activity rather than a new Fortinet vulnerability, while the SOCRadar/BleepingComputer sniffer details explain what attackers can do after they already have sufficient access. The public record does not establish one universal initial-access path for every affected device.
Question: Is sniffing how the attacker initially got in? Source-Backed Answer: Not necessarily. Fortinet's public framing points to credential reuse and brute-force activity rather than a new Fortinet vulnerability, while the SOCRadar/BleepingComputer sniffer details explain what attackers can do after they already have sufficient access. The public record does not establish one universal initial-access path for every affected device. What To Collect: Separate first access from post-access harvesting: review prior credential exposure, brute-force attempts, successful VPN/admin logins, historical CVE exposure, configuration changes, and later packet-capture activity.[13] [25] [26]
Does FortiGate have a built-in sniffer?
Yes. BleepingComputer's report describes FortigateSniffer abusing FortiOS's legitimate diagnostic packet-sniffing functionality and processing the output through SNIFTRAN/PCAP workflows. The defensive issue is abuse of normal administrator troubleshooting capability after access, not necessarily deployment of a traditional malware sniffer.
Question: Does FortiGate have a built-in sniffer? Source-Backed Answer: Yes. BleepingComputer's report describes FortigateSniffer abusing FortiOS's legitimate diagnostic packet-sniffing functionality and processing the output through SNIFTRAN/PCAP workflows. The defensive issue is abuse of normal administrator troubleshooting capability after access, not necessarily deployment of a traditional malware sniffer. What To Collect: Look for unexpected diagnostic packet-capture command use, PCAP/export artifacts, abnormal SSH/admin sessions, and gaps in FortiGate audit or command logging.[25] [26]
What logs can reveal this behavior?
The public sources do not provide a universal FortiGate query pack, but the source-backed hunt path is clear: preserve management-plane activity and correlate packet-capture windows with authentication traffic and follow-on credential use. Canada's Cyber Centre separately reinforces account inventory, suspicious-account review, session termination, password resets, and reporting matching activity.
Question: What logs can reveal this behavior? Source-Backed Answer: The public sources do not provide a universal FortiGate query pack, but the source-backed hunt path is clear: preserve management-plane activity and correlate packet-capture windows with authentication traffic and follow-on credential use. Canada's Cyber Centre separately reinforces account inventory, suspicious-account review, session termination, password resets, and reporting matching activity. What To Collect: Collect FortiGate system/admin logs, SSH/web-admin access logs, configuration-change records, admin-account changes, command/audit history where available, VPN logs, SIEM forwarding status, and downstream AD/RADIUS/LDAP/Kerberos authentication records.[14] [25] [26] [45]
These questions address the practical FortigateSniffer scoping issues that naturally come up after the TTP review: whether sniffing was initial access, why attackers would use it, what FortiGate functionality is being abused, and which evidence should be preserved.
CVE / Vulnerability References
CISA KEV listing
No KEV entry is supported by retained evidence; CISA issued a hardening alert rather than a KEV listing.
Reference: CISA KEV listing Source-Backed Status: No KEV entry is supported by retained evidence; CISA issued a hardening alert rather than a KEV listing. Defender Meaning: Do not claim KEV status for FortiBleed from this record.[14]
FortiBleed CVE
Fortinet states the activity is not a new Fortinet vulnerability; Canadian Cyber Centre references older Fortinet CVEs for firmware review but does not identify FortiBleed as a new CVE.
Reference: FortiBleed CVE Source-Backed Status: Fortinet states the activity is not a new Fortinet vulnerability; Canadian Cyber Centre references older Fortinet CVEs for firmware review but does not identify FortiBleed as a new CVE. Defender Meaning: Response should not wait for CVE publication, and older Fortinet CVE patch review should run alongside credential/session response.[13] [45]
Confirmed Fortinet zero-day
Fortinet says the activity is not related to any recent incident or advisory.
Reference: Confirmed Fortinet zero-day Source-Backed Status: Fortinet says the activity is not related to any recent incident or advisory. Defender Meaning: Treat as credential exposure and possible credential abuse unless new evidence changes the assessment.[13]
Patch-only remediation
CISA's actions focus on sessions, passwords, MFA, and logs; Fortinet frames weak credential hygiene as central; Canadian Cyber Centre adds account inventory, suspicious-account removal, access restriction, and firmware review.
Reference: Patch-only remediation Source-Backed Status: CISA's actions focus on sessions, passwords, MFA, and logs; Fortinet frames weak credential hygiene as central; Canadian Cyber Centre adds account inventory, suspicious-account removal, access restriction, and firmware review. Defender Meaning: Credential rotation, MFA, access restriction, log review, account review, and firmware validation are central.[13] [14] [45]
IOCs / Observables
Exposure lead
Named-company examples reported in screenshots or public summaries, including Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, Oracle, Siemens, Lenovo, Spotify, and Sony.
IOC Type: Exposure lead Indicator: Named-company examples reported in screenshots or public summaries, including Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, Oracle, Siemens, Lenovo, Spotify, and Sony. What To Hunt / Collect: Treat named organizations as scoping leads, not proof of compromise. Affected organizations should validate owned domains, Fortinet/FortiGate URLs, account names, credential status, and internal login history. Source / Use: Use for prioritizing private outreach and scoping only; public naming does not prove successful access.[4] [6] [16]
Exposure lead
6-Jul-2026 · Added Reported UK Foreign Office and local-government account examples in July 5 UK press coverage.
IOC Type: Exposure lead Indicator: 6-Jul-2026 · Added Reported UK Foreign Office and local-government account examples in July 5 UK press coverage. What To Hunt / Collect: For public-sector and critical-infrastructure scoping, validate owned Fortinet/FortiGate URLs, VPN/admin accounts, credential age, MFA state, brute-force evidence, active sessions, admin changes, and local impact telemetry before making public impact statements. Source / Use: Use as reported public-sector context only; do not publish raw account lists, credentials, sensitive dataset rows, or organization-specific compromise conclusions.[37] [38]
Dataset observable
Reported Fortinet/FortiGate firewall or SSL VPN URLs and affected domains.
IOC Type: Dataset observable Indicator: Reported Fortinet/FortiGate firewall or SSL VPN URLs and affected domains. What To Hunt / Collect: Map any discovered URLs or domains to owned Fortinet appliances, public management interfaces, SSL VPN endpoints, business owners, and current exposure state. Source / Use: Core scoping observable from public reporting and lookup workflow.[4] [6] [9] [10] [16]
Credential observable
Usernames, email addresses, plaintext passwords in many cases, and device-related metadata reportedly present in the dataset.
IOC Type: Credential observable Indicator: Usernames, email addresses, plaintext passwords in many cases, and device-related metadata reportedly present in the dataset. What To Hunt / Collect: Collect Fortinet local/admin users, VPN users, firewall-administration accounts, matching email accounts, password rotation history, MFA enrollment, and reuse indicators. Source / Use: High-priority identity and access review pivots.[3] [4] [5] [16]
Credential-pattern observable
23-Jun-2026 · Added SOCRadar's username table highlights admin-like masked values and Fortinet/FortiGate-themed account names among common exposed username patterns.
IOC Type: Credential-pattern observable Indicator: 23-Jun-2026 · Added SOCRadar's username table highlights admin-like masked values and Fortinet/FortiGate-themed account names among common exposed username patterns. What To Hunt / Collect: Review default admin, shared administrator, Fortinet/FortiGate-themed service, local firewall-admin, and VPN account names. Rotate or disable stale accounts, enforce MFA, and review successful login and configuration-change history. Source / Use: Use as a scoping and account-hygiene signal, not a blocklist or proof of compromise.[12]
Behavioral / tool observable
22-Jun-2026 · Added FortigateSniffer-style packet capture and credential extraction activity.
IOC Type: Behavioral / tool observable Indicator: 22-Jun-2026 · Added FortigateSniffer-style packet capture and credential extraction activity. What To Hunt / Collect: Review FortiGate administrative command history and logs for suspicious or unauthorized diagnostic packet-capture use, especially diagnose sniffer packet activity, PCAP exports, unusual SSH/admin access, and credential-capture windows around suspected exposure. Source / Use: Delta hunt lead from SOCRadar and BleepingComputer; not a standalone blocklist IOC.[25] [26] [28]
Behavioral / recovered-tooling observable
24-Jun-2026 · Added CyberStrike Harvester and associated post-authentication credential workflow.
IOC Type: Behavioral / recovered-tooling observable Indicator: 24-Jun-2026 · Added CyberStrike Harvester and associated post-authentication credential workflow. What To Hunt / Collect: Look for credential-stuffing/spraying bursts, FortiGate configuration harvesting, offline cracking workflow traces, AD/SMB follow-on tooling, credential-cleaning scripts, Hashcat or Hashtopolis activity, and unusual file-share access after FortiGate access. Source / Use: Arctic Wolf reverse-engineering lead; publish behavior-level hunting only, not raw recovered artifacts or sensitive infrastructure.[31]
Persistence observable
7-Aug-2026 · Added Fortinet-service-like administrator account names: forticloud-sync, forticloud-tech, support_fortinet, fgtsecure, fgtsec, Technical_support, fortinetadmin, adminin, and tech-fortinet.
IOC Type: Persistence observable Indicator: 7-Aug-2026 · Added Fortinet-service-like administrator account names: forticloud-sync, forticloud-tech, support_fortinet, fgtsecure, fgtsec, Technical_support, fortinetadmin, adminin, and tech-fortinet. What To Hunt / Collect: Check FortiGate local administrators, VPN users, recent account-creation events, privilege changes, password resets, active sessions, and configuration diffs for these names and visually similar variants. Source / Use: CybelAngel persistence-review lead; use as local hunt terms after an exposure match or suspicious admin activity, not as public proof of compromise.[42]
Credential-harvest observable
22-Jun-2026 · Added Credential capture across multiple protocols, including cleartext protocols and hash-bearing authentication material.
IOC Type: Credential-harvest observable Indicator: 22-Jun-2026 · Added Credential capture across multiple protocols, including cleartext protocols and hash-bearing authentication material. What To Hunt / Collect: Scope for FTP, HTTP Basic, LDAP, MSSQL, PostgreSQL, SMTP, Telnet, NTLM, Kerberos, RDP/CredSSP, POP3, IMAP, SIP, Redis, MQTT, and other protocol use crossing Fortinet edge devices during suspected capture windows. Source / Use: SOCRadar reports credential harvesting across 24 protocols; use only for scoping and log-review prioritization.[25]
Tradecraft observable
23-Jun-2026 · Added Access-broker infrastructure touching non-Fortinet services and post-access identity material.
IOC Type: Tradecraft observable Indicator: 23-Jun-2026 · Added Access-broker infrastructure touching non-Fortinet services and post-access identity material. What To Hunt / Collect: For confirmed Fortinet exposure, also review adjacent Synology, Sophos, MSSQL, AD, LDAP, Kerberos/NTLM, session-replay, and password-cracking evidence that could indicate broader hands-on activity. Source / Use: SpyCloud expansion signal; not a public blocklist IOC and not proof that every exposed organization had broader compromise.[29]
Behavioral observable
Unexpected successful Fortinet SSL VPN or firewall-admin logins, suspicious active sessions, admin account creation, privilege changes, policy changes, password changes, and configuration changes.
IOC Type: Behavioral observable Indicator: Unexpected successful Fortinet SSL VPN or firewall-admin logins, suspicious active sessions, admin account creation, privilege changes, policy changes, password changes, and configuration changes. What To Hunt / Collect: Review Fortinet SSL VPN logs, firewall-administration logs, admin-login logs, password-change history, configuration-change logs, source IP/geolocation context, and session duration for exposed or suspected accounts. Source / Use: Operational validation path; this brief does not retain attacker IPs, hashes, blocklist domains, raw artifacts, or a reliable public count of successful credential use or firewall changes.[8] [12] [14] [16] [31] [34]
Caveat
No retained blocklist-grade attacker infrastructure IOCs.
IOC Type: Caveat Indicator: No retained blocklist-grade attacker infrastructure IOCs. What To Hunt / Collect: Do not publish named companies, domains, or dataset rows as malicious IOCs. Use them as exposure leads and validate through internal telemetry. Source / Use: The retained sources support scoping observables, not deterministic blocking indicators.
IOC note: this brief does not retain blocklist-grade attacker indicators such as file hashes, attacker-controlled IP addresses, victim paths, recovered credentials, phishing domains, or confirmed malicious URLs. The entries below are exposure leads, dataset observables, credential pivots, and behavioral hunt leads that require local validation before enforcement.
Threat Actor Glossary
30-Jun-2026 · Revised SOCRadar-named attribution now exists
SOCRadar attribution; not universal victim-impact attribution.
Actor / Cluster: 30-Jun-2026 · Revised SOCRadar-named attribution now exists Source-Backed Role: SOCRadar attribution; not universal victim-impact attribution. What Is Known: The retained public record supports a reported Fortinet/FortiGate credential-exposure dataset and possible operational infrastructure. SOCRadar now attributes FortiBleed to Lynx / INC; SOCRadar's July 2 update links FortiBleed infrastructure to INC/Lynx ransomware operations through a shared operator and overlapping victim data; SpyCloud adds a SantaAd marketplace signal, and Recorded Future/Insikt assesses SantaAd as likely credible while separately warning about low-credibility copycat or re-extortion claims. That still is not confirmed attribution to every FortiBleed activity or downstream intrusion. Attribution Boundary: Use the Lynx / INC label as SOCRadar's current attribution, not as proof for every organization-specific event.[8] [12] [13] [29] [34] [36]
30-Jun-2026 · Revised Lynx / INC
SOCRadar-attributed ransomware grouping for FortiBleed.
Actor / Cluster: 30-Jun-2026 · Revised Lynx / INC Source-Backed Role: SOCRadar-attributed ransomware grouping for FortiBleed. What Is Known: SOCRadar's June 29 update states that it attributes FortiBleed to Lynx / INC. Its July 2 update says a FortiBleed-linked operator was active in INC Ransom and Lynx negotiation panels, with at least 12 ransomware deployments stemming from FortiBleed-derived access. Attribution Boundary: Do not expand this into victim-specific intrusion or ransomware attribution without local telemetry or additional primary corroboration.[12] [36]
22-Jul-2026 · Added SOCRadar-named operator context
SOCRadar source-backed operator and workflow analysis; not organization-specific attribution.
Actor / Cluster: 22-Jul-2026 · Added SOCRadar-named operator context Source-Backed Role: SOCRadar source-backed operator and workflow analysis; not organization-specific attribution. What Is Known: CSO Online reported SOCRadar found an operational server containing stolen FortiGate passwords, tools, automation infrastructure, a victim list, and attribution-relevant information. SOCRadar's public Volume II landing page now says the report identifies key operators such as TOXMAN and maps internal hierarchy and victim-management workflows. Attribution Boundary: Use as SOCRadar operation-context attribution only; do not publish raw operator artifacts, infrastructure, victim rows, credentials, or claim organization-specific impact from this alone.[8] [12] [40]
22-Jun-2026 · Added Likely Russian-speaking multi-operator crew
SOCRadar assessment of current operation language, tooling, and working pattern.
Actor / Cluster: 22-Jun-2026 · Added Likely Russian-speaking multi-operator crew Source-Backed Role: SOCRadar assessment of current operation language, tooling, and working pattern. What Is Known: SOCRadar's newer analysis characterizes the operation as Russian-speaking and multi-operator with initial-access-broker-style packaging; SpyCloud separately reports Russian-language tooling and SantaAd forum activity as access-broker signal; Arctic Wolf reports Russian-language UI/status strings and an operator handle as low-confidence Russian-speaking indicators. Attribution Boundary: Use as an analytic assessment, not as court-ready attribution.[25] [28] [29] [31]
23-Jun-2026 · Added SantaAd forum account
Reported marketplace signal, not confirmed campaign attribution.
Actor / Cluster: 23-Jun-2026 · Added SantaAd forum account Source-Backed Role: Reported marketplace signal, not confirmed campaign attribution. What Is Known: SpyCloud reports that SantaAd, a Russian-speaking access-broker account on Exploit, implied responsibility and referenced public FortiBleed reporting while adjusting pricing. 26-Jun-2026 · Revised Recorded Future/Insikt assesses SantaAd as likely credible for a FortiBleed-related sale claim but separately flags a low-credibility copycat/re-extortion claim. 7-Aug-2026 · Revised CybelAngel also attributes the campaign publicly to SantaAd and ties exposed infrastructure to SantaAd activity based on converging indicators; keep this as source-level attribution. Attribution Boundary: Do not treat this as confirmed attribution to every intrusion, publish marketplace artifacts, or infer all listed devices were successfully sold or used.[29] [34] [42]
Potential credential users or buyers
Hypothetical downstream users of exposed Fortinet credentials.
Actor / Cluster: Potential credential users or buyers Source-Backed Role: Hypothetical downstream users of exposed Fortinet credentials. What Is Known: The dataset format and reported lookup/scoping context create concern that exposed credentials could be used for unauthorized VPN or firewall access if still valid. Attribution Boundary: No retained source proves resale, buyer identity, or successful use by a specific actor.[4] [6] [10] [14] [16]
Named researchers and companies
Sources, reporters, researchers, vendors, or responders.
Actor / Cluster: Named researchers and companies Source-Backed Role: Sources, reporters, researchers, vendors, or responders. What Is Known: Diachenko, Hudson Rock, SOCRadar, Kevin Beaumont, Fortinet, CISA, and media outlets are treated as sources or responders elsewhere in this brief. Attribution Boundary: Do not list them as threat actors.[9] [10] [11] [12] [13] [14] [15]
Talking Points
Executives
FortiBleed should be managed as an edge-access credential exposure, not as a routine patch notice.
Target Audience: Executives Message: FortiBleed should be managed as an edge-access credential exposure, not as a routine patch notice. Why It Matters: Exposed VPN/firewall credentials can create direct network-entry risk even without a new CVE. Action / Ask: Approve session termination, credential rotation, MFA enforcement, exposure validation, temporary access restrictions, and account inventory.[13] [14] [45]
Security Operations
Reported data includes usernames, emails, plaintext passwords in many cases, and Fortinet/FortiGate URL or domain associations.
Target Audience: Security Operations Message: Reported data includes usernames, emails, plaintext passwords in many cases, and Fortinet/FortiGate URL or domain associations. Why It Matters: These fields provide concrete pivots for account and asset scoping. Action / Ask: Correlate Fortinet account lists, VPN/admin logs, public Fortinet URLs, affected domains, and MFA status.[3] [4] [5] [6] [16]
DFIR / Network Security
22-Jun-2026 · Added New SOCRadar/BleepingComputer reporting adds a FortigateSniffer and diagnostic packet-capture hunting angle.
Target Audience: DFIR / Network Security Message: 22-Jun-2026 · Added New SOCRadar/BleepingComputer reporting adds a FortigateSniffer and diagnostic packet-capture hunting angle. Why It Matters: The updated story is no longer only a static credential list. Sniffing appears to be a post-compromise scaling behavior: after management access, the firewall's own packet-capture function can be abused to harvest additional credentials from traffic crossing the edge. Action / Ask: Preserve and review FortiGate admin command history, `diagnose sniffer packet` activity, PCAP exports, SSH/admin sessions, and protocol-specific authentication windows.[25] [26] [28]
Scoping Call / Affected Organization
Use source-backed pivots: owned domains, public Fortinet/FortiGate firewall or SSL VPN URLs, affected-domain data, Hudson Rock's lookup portal, usernames, emails, plaintext password exposure, active sessions, and internal Fortinet logs.
Target Audience: Scoping Call / Affected Organization Message: Use source-backed pivots: owned domains, public Fortinet/FortiGate firewall or SSL VPN URLs, affected-domain data, Hudson Rock's lookup portal, usernames, emails, plaintext password exposure, active sessions, and internal Fortinet logs. Why It Matters: A lookup hit can accelerate containment, but it does not by itself prove successful compromise; a negative lookup does not prove absence. Action / Ask: Bring domain inventory, public Fortinet URL inventory, Fortinet account exports, active-session inventory, authentication logs, admin-change logs, MFA enrollment status, suspicious-account review, and password-rotation history.[10] [14] [45]
Sophos Firewall Scoping
23-Jun-2026 · Added If a Sophos Firewall/VPN case involves valid credentials, do not assume a Sophos exploit or a direct FortiBleed match.
Target Audience: Sophos Firewall Scoping Message: 23-Jun-2026 · Added If a Sophos Firewall/VPN case involves valid credentials, do not assume a Sophos exploit or a direct FortiBleed match. Why It Matters: Sophos says the same threat actors targeted internet-exposed Sophos Firewall appliances through user-level credential brute-forcing/stuffing, but it had not observed compromise or Sophos Firewall vulnerability exploitation in reviewed telemetry. Action / Ask: Collect Sophos Firewall Admin/User/VPN portal exposure, MFA enrollment evidence, successful and failed auth logs, VPN sessions, IdP logs, credential-reuse evidence, and any Fortinet overlap before attribution.[30]
Legal / Communications
Public lists or screenshots may name organizations, but dataset inclusion is not the same as confirmed breach.
Target Audience: Legal / Communications Message: Public lists or screenshots may name organizations, but dataset inclusion is not the same as confirmed breach. Why It Matters: Premature victim statements can overstate facts or understate risk. Action / Ask: Prepare conditional messaging that distinguishes exposure match, credential validity, successful login, and confirmed impact.[4] [6] [16]
Scoping Call Talk Track
“FortiBleed should be treated first as a Fortinet/FortiGate credential-exposure and remote-access scoping event, not as proof that every named organization was breached. The public reporting points to a large dataset tied to Fortinet firewall or SSL VPN URLs, affected domains, usernames, email addresses, and plaintext passwords in many cases. That means our first job is to determine whether the client has any public Fortinet/FortiGate URLs, SSL VPN endpoints, internet-facing management interfaces, domains, or account names that overlap with the reported exposure.
The most important distinction for counsel is exposure versus impact. A dataset or lookup match may justify urgent containment, but it does not automatically prove a successful login, persistence, data access, or exfiltration. We should preserve and review Fortinet VPN and admin-login logs, active sessions, admin account changes, configuration changes, MFA status, and password-rotation history before making stronger factual statements. Fortinet has publicly framed this as not a new Fortinet vulnerability, while CISA still recommends hardening steps because valid or reused credentials can be operationally dangerous.
For immediate action, we should validate exposure, terminate active SSL VPN and administrative sessions where appropriate, rotate Fortinet VPN and admin credentials, check for credential reuse, enforce phishing-resistant MFA, restrict public management access, and hunt for unexpected successful logins or configuration changes. The client-facing message should stay disciplined: we are investigating a source-backed credential exposure, separating public dataset claims from client-specific telemetry, and moving quickly on containment steps that are prudent even before final impact is known.”
22-Jun-2026 · Added “The newer SOCRadar/BleepingComputer update adds a FortigateSniffer angle. For scoping, that means we should not stop at domain lookup or password rotation; we should also ask whether FortiGate diagnostic packet capture was invoked, whether PCAP exports exist, whether SSH/admin sessions look abnormal, and whether credential-bearing protocols were captured during the suspected window.”
Executive Talk Track
“The practical executive takeaway is that FortiBleed is not currently framed by Fortinet as a new Fortinet vulnerability, but it is still a serious access-risk event. The concern is that Fortinet VPN or firewall-administration credentials may be exposed in public reporting, and if any of those credentials are still valid or reused, attackers could gain access to an important edge-control point.
Our immediate objective is not to prove every public claim; it is to reduce risk while we validate. That means identifying whether we operate affected Fortinet/FortiGate services, checking domains and public URLs against trusted lookup paths, rotating relevant VPN and admin credentials, enforcing MFA, restricting management exposure, and reviewing logs for signs of successful access or configuration changes. We should communicate carefully: exposure is not the same as confirmed compromise, but it is enough to justify urgent action.”
Threat Intel Talk Track
“From a threat-intelligence perspective, the strongest source-backed frame is a credential-exposure dataset and possible operational infrastructure around Fortinet/FortiGate SSL VPN and firewall access. The retained sources support scale, exposed credential fields, affected-domain scoping, researcher discovery context, lookup workflows, and remediation guidance, but they do not give us clean attacker infrastructure IOCs such as hashes, IP addresses, malware filenames, phishing domains, or confirmed malicious URLs.
The useful pivots are therefore not blocklists; they are exposure and behavior pivots. We should enrich owned domains, public Fortinet URLs, VPN and admin-account inventories, authentication logs, session records, configuration-change events, credential-rotation history, and MFA state. If we are an MSP, insurer, breach counsel, incident-response provider, or any organization responsible for a portfolio of clients, policyholders, subsidiaries, or vendors, we should cross-reference the reported leak lists and lookup results against internal customer, domain, asset, and policyholder inventories so we can prioritize outreach and follow-up action. We should keep the attribution boundary tight: there is no named intrusion set in the retained evidence, and public company names or screenshots should be treated as scoping leads rather than proof of successful compromise.”
Insurance Claims Talk Track
“For claims intake, FortiBleed should be triaged as a potential remote-access credential exposure, not automatically as a confirmed network breach. The key questions are whether the insured uses Fortinet or FortiGate SSL VPN, whether any public Fortinet management or VPN endpoints match the reported exposure, whether affected credentials were valid or reused, and whether there is evidence of successful login, persistence, configuration change, or downstream data access.
The claims file should preserve the distinction between exposure, credential validity, unauthorized access, and impact. Useful evidence includes asset inventory, public URL/domain matches, Fortinet account lists, password-rotation timestamps, MFA coverage, SSL VPN and admin-login logs, active-session records, configuration-change history, and any vendor or incident-response validation. Coverage and notice discussions should be based on what the insured telemetry confirms, not only on public dataset references or named-company reporting.”
Decision Ready Actions
CISO / Security Lead
Immediate
Target Persona: CISO / Security Lead Timeframe: Immediate Decision / Action: Open a FortiBleed exposure-validation workstream for all Fortinet/FortiGate SSL VPN and internet-facing admin assets. Evidence Needed: Public Fortinet URL inventory, owned domains, FortiGate SSL VPN inventory, exposed management-interface list, business-owner mapping. Success Criteria: All public Fortinet access points are identified, owned, and assigned for validation.[3] [4] [5] [6] [16]
Threat Intelligence / SOC
Immediate
Target Persona: Threat Intelligence / SOC Timeframe: Immediate Decision / Action: Check trusted credential-intelligence sources and the Hudson Rock FortiBleed lookup portal for owned domains. Evidence Needed: Owned domains, known Fortinet/FortiGate URLs, domain-ownership proof if required, credential-intelligence query results. Success Criteria: Positive matches are escalated to incident response; negative results are documented with source limitations.[10]
IAM / Network Security
Immediate
Target Persona: IAM / Network Security Timeframe: Immediate Decision / Action: Terminate active SSL VPN/admin sessions, rotate Fortinet VPN/admin passwords, and address any reused passwords tied to exposed usernames, emails, or Fortinet accounts. Evidence Needed: Fortinet local/admin user list, VPN user list, email-linked account list, password-change timestamps, password-reuse review. Success Criteria: High-risk sessions are terminated, Fortinet credentials are rotated, and reuse exposure is reduced.[13] [14]
SOC / Incident Response
24 to 72 hours
Target Persona: SOC / Incident Response Timeframe: 24 to 72 hours Decision / Action: Review unexpected successful admin and VPN logins involving Fortinet accounts. Evidence Needed: Fortinet SSL VPN logs, admin-login logs, source IP/geolocation context, account names, timestamps, MFA results, failed/successful login patterns. Success Criteria: Suspicious logins are triaged, contained, and linked to account and asset remediation.[3] [4] [6] [8]
Network Security / IR
24 to 72 hours
Target Persona: Network Security / IR Timeframe: 24 to 72 hours Decision / Action: Review admin account creation, privilege changes, policy changes, configuration changes, and suspicious long-lived VPN sessions. Evidence Needed: Fortinet configuration-change logs, admin audit logs, account-creation records, VPN session logs, policy-change records. Success Criteria: Unauthorized changes or sessions are identified, reverted, and investigated.[8]
Network Security / DFIR
24 to 72 hours
Target Persona: Network Security / DFIR Timeframe: 24 to 72 hours Decision / Action: 22-Jun-2026 · Added Add FortigateSniffer-specific checks for diagnostic packet capture, PCAP exports, SSH/admin access, and credential-harvesting protocol windows. Evidence Needed: FortiGate admin command history, diagnose sniffer packet usage, PCAP/export artifacts, SSH/admin session logs, SIEM coverage, and protocol-specific authentication logs. Success Criteria: Packet-capture abuse is confirmed, refuted, or bounded by source, account, time window, protocol, and affected assets.[25] [26]
Sophos Firewall / MDR Scopers
Immediate
Target Persona: Sophos Firewall / MDR Scopers Timeframe: Immediate Decision / Action: 23-Jun-2026 · Added For Sophos Firewall incidents involving valid credentials, validate MFA enrollment and portal-specific exposure before calling it FortiBleed. Evidence Needed: Sophos Firewall Admin/User/VPN portal exposure, MFA enrollment and bypass evidence, user-level authentication logs, failed/successful brute-force patterns, VPN sessions, and credential-reuse checks. Success Criteria: Credential-stuffing exposure is separated from confirmed compromise, and Sophos-specific findings remain aligned with Sophos's advisory boundary.[30]
Exploitable Technology Risks
FortiGate SSL VPN and firewall administration
Credentials tied to SSL VPN access and firewall-administration paths reportedly appear in the dataset.
Technology / Trust Path: FortiGate SSL VPN and firewall administration Source-Supported Risk: Credentials tied to SSL VPN access and firewall-administration paths reportedly appear in the dataset. Defensive Priority: Inventory endpoints, rotate VPN and firewall-admin credentials, enforce MFA, and review VPN/admin authentication logs. Evidence / Caveat: Reporting does not prove every credential is valid, current, or successfully used.[3] [4] [5] [16]
Fortinet account credentials
Usernames, emails, and plaintext passwords in many cases are reportedly exposed.
Technology / Trust Path: Fortinet account credentials Source-Supported Risk: Usernames, emails, and plaintext passwords in many cases are reportedly exposed. Defensive Priority: Rotate Fortinet firewall-admin and VPN passwords and investigate password reuse across other systems. Evidence / Caveat: Not all records are proven to contain plaintext passwords, and no reliable public count establishes successful use or attacker password changes.[3] [4] [5] [16]
Fortinet/FortiGate firewall URLs
Reporting cites 73,932 firewall or SSL VPN URLs.
Technology / Trust Path: Fortinet/FortiGate firewall URLs Source-Supported Risk: Reporting cites 73,932 firewall or SSL VPN URLs. Defensive Priority: Map public URLs to actual owned appliances and business owners before impact decisions. Evidence / Caveat: URL count is not the same as confirmed unique physical device count.[3] [4] [6]
Internet-facing Fortinet administration
Exposed administrative interfaces are highlighted as priority review targets.
Technology / Trust Path: Internet-facing Fortinet administration Source-Supported Risk: Exposed administrative interfaces are highlighted as priority review targets. Defensive Priority: Restrict management access from the public internet and audit admin logins and account changes. Evidence / Caveat: Retained reporting does not provide exact configuration commands or baselines.[3]
22-Jun-2026 · Added FortiOS diagnostic packet capture
SOCRadar and BleepingComputer describe FortigateSniffer abusing legitimate FortiOS packet-capture functionality to collect credential-bearing traffic.
Technology / Trust Path: 22-Jun-2026 · Added FortiOS diagnostic packet capture Source-Supported Risk: SOCRadar and BleepingComputer describe FortigateSniffer abusing legitimate FortiOS packet-capture functionality to collect credential-bearing traffic. Defensive Priority: Audit FortiGate administrative command use, diagnose sniffer packet activity, PCAP exports, SSH/admin access, and captured protocols during suspicious windows. Evidence / Caveat: This is a behavioral and forensic lead, not a public blocklist IOC.[25] [26]
23-Jun-2026 · Added Internet-exposed Sophos Firewall portals
Sophos reports adjacent targeting of user-level accounts on exposed Sophos Firewall appliances through credential brute-forcing/stuffing.
Technology / Trust Path: 23-Jun-2026 · Added Internet-exposed Sophos Firewall portals Source-Supported Risk: Sophos reports adjacent targeting of user-level accounts on exposed Sophos Firewall appliances through credential brute-forcing/stuffing. Defensive Priority: Verify whether MFA is enforced and enrolled for Sophos Firewall Admin, User, and VPN portals; review failed/successful authentication, lockouts, and valid-credential use. Evidence / Caveat: Sophos reports no observed Sophos Firewall compromise or vulnerability exploitation in reviewed telemetry so far.[30]
Tier 0 Through Tier 8 Source Summary
Tier 0
Highest-authority primary/vendor/government sources
Tier: Tier 0 Trust Role: Highest-authority primary/vendor/government sources Retained Sources: Fortinet PSIRT; CISA; UK NCSC; Canadian Centre for Cyber Security What This Tier Supports: Official vendor and government framing: Fortinet says this is not a new Fortinet vulnerability; CISA provides hardening actions for sessions, credentials, MFA, and logs; NCSC adds UK-focused checker, IoC review, isolation/factory-reset, shared-credential, MFA, management-hardening, and PBKDF2 guidance; Canada Cyber Centre adds account inventory, suspicious-account removal, management-interface restriction, session termination, password reset, MFA, firmware review, gateway defense, privilege-management, and reporting guidance. Caveats: These sources do not prove successful compromise at every listed organization.
Tier 1
High-trust primary technical or authoritative sources
Tier: Tier 1 Trust Role: High-trust primary technical or authoritative sources Retained Sources: Hudson Rock; Diachenko LinkedIn; SOCRadar; Kevin Beaumont; SpyCloud Labs; Recorded Future Insikt Group What This Tier Supports: Primary/near-primary discovery, lookup, operational-server, credential-validation, infrastructure, IAB-style monetization, seller-credibility deconfliction, active-operation campaign-card metrics, SOCRadar Lynx / INC attribution, and configuration-export context. Caveats: Organization-specific impact still requires internal telemetry and domain/account validation; SOCRadar's Lynx / INC attribution should not be applied universally to every listed exposure or downstream intrusion.
Tier 2
Specialist security reporting and vendor/security blogs
Tier: Tier 2 Trust Role: Specialist security reporting and vendor/security blogs Retained Sources: Threat-Modeling.com, Kudelski Security, ITKnowledgeBases What This Tier Supports: General public framing, explicit non-CVE caveat, affected asset types, and initial defensive actions. Caveats: Use ITKnowledgeBases most heavily in this tier; Kudelski excerpt was not substantive.
Tier 3
Mainstream security and technology media
Tier: Tier 3 Trust Role: Mainstream security and technology media Retained Sources: BleepingComputer, CyberUnit, Hackread, DataBreaches.net, CSO Online, Security Affairs What This Tier Supports: Core scale, exposed data types, discovery parties, lookup-portal lead, persistent-access concern, named-company examples, and configuration-export discussion. Caveats: Several claims are secondary references to stronger primary or practitioner sources.
Tier 4
Aggregators or lower-confidence public summaries
Tier: Tier 4 Trust Role: Aggregators or lower-confidence public summaries Retained Sources: 0 retained What This Tier Supports: No retained evidence from this tier. Caveats: None used.
Tier 5
User-provided or internal sources
Tier: Tier 5 Trust Role: User-provided or internal sources Retained Sources: 0 retained What This Tier Supports: No user-provided URLs or internal evidence. Caveats: No private validation of organizational exposure.
Tier 6
Broad web or weakly relevant sources
Tier: Tier 6 Trust Role: Broad web or weakly relevant sources Retained Sources: 0 retained What This Tier Supports: No retained evidence from this tier. Caveats: None used.
Tier 7
Unverified or unattributed sources
Tier: Tier 7 Trust Role: Unverified or unattributed sources Retained Sources: 0 retained What This Tier Supports: No retained evidence from this tier. Caveats: No underground, social, or anonymous-source claims used.
22-Jun-2026 · Added Tier 8
Expansion Research / AI Agent delta sources
Tier: 22-Jun-2026 · Added Tier 8 Trust Role: Expansion Research / AI Agent delta sources Retained Sources: Huntress, WaterISAC, Field Effect, Arctic Wolf, HKCERT, SecurityWeek, Bitsight, IBM X-Force, SOCRadar STRU update, BleepingComputer update, SOCRadar FortiBleed Check, SOCRadar Campaigns, Security Affairs update, SpyCloud Labs, Sophos, Recorded Future Insikt Group, Unit 42, SOCRadar INC/Lynx ransomware-link update, The Times, The Sun, Roche Diagnostics, BGD e-GOV CIRT, Canadian Centre for Cyber Security What This Tier Supports: Enhanced scoping, partner/customer matching, FortigateSniffer operation detail, updated scale metrics, packet-capture hunting, access-broker infrastructure, Sophos Firewall credential-stuffing boundaries, exposure-check workflow, campaign-card metric tracking, marketplace-claim deconfliction, ransomware-link escalation, reported UK public-sector exposure context, Bangladesh regional-CERT exposure scoping, official Canadian response guidance, and first-party customer-impact deconfliction. Caveats: Use to add depth and deltas; do not let expansion sources override Fortinet/CISA/NCSC/Canadian Cyber Centre on official response and vulnerability-status guidance or Sophos on Sophos Firewall vulnerability/compromise status, and do not convert media-reported or regional tagged-address examples into confirmed compromise claims.
Source Reconciliation
Strong source agreement
The retained public record consistently supports a large Fortinet/FortiGate credential-exposure story involving firewall or SSL VPN URLs, affected domains, and exposed credential fields.
Source Issue: Strong source agreement Agreement / Difference: The retained public record consistently supports a large Fortinet/FortiGate credential-exposure story involving firewall or SSL VPN URLs, affected domains, and exposed credential fields. Tension or Contradiction: Sources differ in headline phrasing, but the core exposure-and-scoping concern is consistent. How To Use It: Use the 73,932 URL figure as the careful baseline, while making clear that URLs are not the same as unique physical devices.[3] [4] [5] [6] [9] [10] [16]
Scale wording mismatch
Several sources use rounded figures such as 73,000, 75,000, or higher firewall/device language, while others describe 73,932 firewall or SSL VPN URLs and roughly 21,632 affected domains.
Source Issue: Scale wording mismatch Agreement / Difference: Several sources use rounded figures such as 73,000, 75,000, or higher firewall/device language, while others describe 73,932 firewall or SSL VPN URLs and roughly 21,632 affected domains. Tension or Contradiction: The public narrative can blur URLs, firewalls, SSL VPN endpoints, domains, and devices. How To Use It: Default to URL-level and domain-level language unless a source specifically proves unique devices.[3] [4] [5] [6] [9] [10] [12] [16]
22-Jun-2026 · Added Static leak vs active operation
The original public story emphasized a credential-exposure dataset; the June 22 SOCRadar/BleepingComputer update adds FortigateSniffer tooling, operation servers, harvesting cycles, protocol capture, and cracking/replay infrastructure. SOCRadar's June 27 campaign card adds unique-device and organizational-domain metric labels, its June 29 checker update adds a scanned-host metric, and its July 20 checker update keeps the same headline metrics while saying new compromised devices are being added.
Source Issue: 22-Jun-2026 · Added Static leak vs active operation Agreement / Difference: The original public story emphasized a credential-exposure dataset; the June 22 SOCRadar/BleepingComputer update adds FortigateSniffer tooling, operation servers, harvesting cycles, protocol capture, and cracking/replay infrastructure. SOCRadar's June 27 campaign card adds unique-device and organizational-domain metric labels, its June 29 checker update adds a scanned-host metric, and its July 20 checker update keeps the same headline metrics while saying new compromised devices are being added. Tension or Contradiction: Both can be true: a public dataset can exist while the underlying operation also continues or has broader infrastructure. How To Use It: Keep the old dataset metrics for exposure scoping and add the new operation metrics for hunting and incident-response posture.[25] [26] [27] [28] [35]
30-Jun-2026 · Revised SOCRadar attribution update
SOCRadar's June 29 update to its original investigation attributes FortiBleed to Lynx / INC. 22-Jul-2026 · Added Newly retained; published >24h before this run: SOCRadar's public Volume II landing page now supports the high-level attribution, operator/hierarchy, victim-workflow, AI-assisted-operation, targeting, ATT&CK, and IoC-availability framing.
Source Issue: 30-Jun-2026 · Revised SOCRadar attribution update Agreement / Difference: SOCRadar's June 29 update to its original investigation attributes FortiBleed to Lynx / INC. 22-Jul-2026 · Added Newly retained; published >24h before this run: SOCRadar's public Volume II landing page now supports the high-level attribution, operator/hierarchy, victim-workflow, AI-assisted-operation, targeting, ATT&CK, and IoC-availability framing. Tension or Contradiction: Earlier retained public sources supported Russian-speaking, access-broker-style, and marketplace-signal assessments but did not name a controlling actor for every FortiBleed exposure or downstream case. How To Use It: Retain the named attribution and Volume II framing as SOCRadar's assessment; keep impact, victim, and intrusion attribution dependent on local logs and stronger corroboration.[12] [40]
2-Jul-2026 · Added Ransomware-link escalation
SOCRadar's July 2 update links FortiBleed infrastructure to INC Ransom and Lynx ransomware operations, reports 200+ additional operational servers, admin-level access on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments.
Source Issue: 2-Jul-2026 · Added Ransomware-link escalation Agreement / Difference: SOCRadar's July 2 update links FortiBleed infrastructure to INC Ransom and Lynx ransomware operations, reports 200+ additional operational servers, admin-level access on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments. Tension or Contradiction: The report adds stronger aggregate impact evidence, and the public Volume II landing page now summarizes operator, hierarchy, AI-assisted-operation, targeting, ATT&CK, and IoC-availability themes without requiring this brief to republish sensitive detail. How To Use It: Use the finding to escalate confirmed exposure into ransomware scoping and recovery review; do not publish raw IOCs, victim lists, detailed operator handles, infrastructure, recovered artifacts, or organization-specific ransomware claims.[36]
22-Jul-2026 · Added SOCRadar Volume II availability
SOCRadar's public Volume II landing page says FortiBleed Unmasked connects harvested FortiGate credentials to Lynx and INC ransomware infrastructure and summarizes operator/hierarchy analysis, victim-management workflows, AI-assisted offensive operations, technical profiling, targeting analysis, MITRE ATT&CK mapping, and IoC availability.
Source Issue: 22-Jul-2026 · Added SOCRadar Volume II availability Agreement / Difference: SOCRadar's public Volume II landing page says FortiBleed Unmasked connects harvested FortiGate credentials to Lynx and INC ransomware infrastructure and summarizes operator/hierarchy analysis, victim-management workflows, AI-assisted offensive operations, technical profiling, targeting analysis, MITRE ATT&CK mapping, and IoC availability. Tension or Contradiction: The source is newly retained in this brief, but public references indicate it was available more than 24 hours before this run and most aggregate ransomware-link metrics were already represented from SOCRadar's July 2 update. How To Use It: Retain it to remove the prior pending-whitepaper caveat and strengthen source support; keep raw IoCs, infrastructure, victim data, recovered artifacts, and detailed operator artifacts out of the public page.[40]
6-Jul-2026 · Added UK public-sector reporting boundary
The Times and The Sun report UK public-sector account examples in a FortiBleed-linked stolen-login cluster, with The Sun saying NCSC issued Fortinet brute-force alerting and that The Telegraph saw list details. Newly retained NCSC guidance directly corroborates UK-focused response steps without validating the media-reported account list.
Source Issue: 6-Jul-2026 · Added UK public-sector reporting boundary Agreement / Difference: The Times and The Sun report UK public-sector account examples in a FortiBleed-linked stolen-login cluster, with The Sun saying NCSC issued Fortinet brute-force alerting and that The Telegraph saw list details. Newly retained NCSC guidance directly corroborates UK-focused response steps without validating the media-reported account list. Tension or Contradiction: The reporting is fresh and relevant for public-sector urgency, but it remains media reporting and does not provide first-party organizational impact statements, raw telemetry, or publishable account-level evidence. How To Use It: Use it to broaden government, critical-infrastructure, and provider scoping; do not publish raw accounts, credentials, list excerpts, or confirmed-impact language without local or first-party confirmation.[37] [38] [39]
26-Aug-2026 · Added Canadian official response guidance
Canada's Cyber Centre alert AL26-014 says the agency became aware on June 17, 2026 of open-source FortiBleed reporting affecting Fortinet firewalls and VPN gateways, and recommends account inventory, suspicious-account removal, management-interface restriction, session termination, password resets, MFA, firmware review, internet-gateway defense, privilege-management, and reporting matching activity through Cyber Centre channels.
Source Issue: 26-Aug-2026 · Added Canadian official response guidance Agreement / Difference: Canada's Cyber Centre alert AL26-014 says the agency became aware on June 17, 2026 of open-source FortiBleed reporting affecting Fortinet firewalls and VPN gateways, and recommends account inventory, suspicious-account removal, management-interface restriction, session termination, password resets, MFA, firmware review, internet-gateway defense, privilege-management, and reporting matching activity through Cyber Centre channels. Tension or Contradiction: The source is official and useful for Canadian response coordination, but it was published on June 18 and does not add a new victim list, compromise count, or FortiBleed CVE. How To Use It: Retain it as official Canadian hardening and reporting guidance; keep Fortinet/CISA controlling the no-new-vulnerability and U.S. federal-response framing, and do not treat old publication as fresh reporting.[45]
24-Jun-2026 · Added Reported tooling vs publishable IOCs
Arctic Wolf adds a recovered-tooling layer, including CyberStrike Harvester, FortiGate Sniffer panel references, AD/SMB tooling, credential cleaners, and cracking workflows. 27-Jun-2026 · Revised Unit 42 separately corroborates password spraying, possible configuration extraction, offline cracking, unvalidated forum-sale claims, and suspicious login attempts in customer telemetry while stating the activity was not targeting Palo Alto Networks devices; its public publication date is June 26.
Source Issue: 24-Jun-2026 · Added Reported tooling vs publishable IOCs Agreement / Difference: Arctic Wolf adds a recovered-tooling layer, including CyberStrike Harvester, FortiGate Sniffer panel references, AD/SMB tooling, credential cleaners, and cracking workflows. 27-Jun-2026 · Revised Unit 42 separately corroborates password spraying, possible configuration extraction, offline cracking, unvalidated forum-sale claims, and suspicious login attempts in customer telemetry while stating the activity was not targeting Palo Alto Networks devices; its public publication date is June 26. Tension or Contradiction: Tool names and workflow details are useful for hunting, but raw hashes, IPs, victim paths, credentials, and acquisition instructions are not appropriate for this public brief. How To Use It: Publish behavior-level hunt guidance and source links; do not convert sensitive recovered artifacts into a public blocklist or victim narrative.[31] [32]
22-Jun-2026 · Revised SOCRadar metric vocabulary
SOCRadar's newer public materials use multiple scale labels, including 59.3M scanned hosts, 430K+ targeted devices, 90K+ IPs, 750K+ credentials, 105M+ records, 80,553 unique devices, 23,406 organizational domains, and 110M+ harvested credential records or credential artifacts.
Source Issue: 22-Jun-2026 · Revised SOCRadar metric vocabulary Agreement / Difference: SOCRadar's newer public materials use multiple scale labels, including 59.3M scanned hosts, 430K+ targeted devices, 90K+ IPs, 750K+ credentials, 105M+ records, 80,553 unique devices, 23,406 organizational domains, and 110M+ harvested credential records or credential artifacts. Tension or Contradiction: These are not all the same measurement unit and should not be summed or collapsed into a single victim/device count. How To Use It: Cite the exact metric label used by the source and separate targeted devices, unique devices, organizational domains, IPs, credentials, records, and harvested artifacts.[25] [27] [35]
23-Jun-2026 · Added Fortinet-only vs broader access-broker operation
SpyCloud reports the same actor infrastructure also targeted Synology NAS, Sophos firewall portals, and MSSQL servers, while FortiGate remained the headline credential set.
Source Issue: 23-Jun-2026 · Added Fortinet-only vs broader access-broker operation Agreement / Difference: SpyCloud reports the same actor infrastructure also targeted Synology NAS, Sophos firewall portals, and MSSQL servers, while FortiGate remained the headline credential set. Tension or Contradiction: The static brief should stay FortiBleed-focused, but affected organizations should not stop scoping at Fortinet logs when exposure is confirmed. How To Use It: Keep Fortinet/CISA controlling the FortiGate guidance; add SpyCloud as a hunt-expansion source for adjacent edge-device, database, AD, session-replay, and password-cracking review.[29]
26-Jun-2026 · Added Marketplace claim credibility
Recorded Future/Insikt assesses one FortiBleed-related seller claim as likely credible while identifying another public claim as likely low-credibility copycat or re-extortion activity that reused prior language. 5-Jul-2026 · Clarified The same source also supports behavior-level workflow and infrastructure scoping, but the public page should not reproduce raw artifacts or acquisition details.
Source Issue: 26-Jun-2026 · Added Marketplace claim credibility Agreement / Difference: Recorded Future/Insikt assesses one FortiBleed-related seller claim as likely credible while identifying another public claim as likely low-credibility copycat or re-extortion activity that reused prior language. 5-Jul-2026 · Clarified The same source also supports behavior-level workflow and infrastructure scoping, but the public page should not reproduce raw artifacts or acquisition details. Tension or Contradiction: Public marketplace or Telegram claims can create urgency but vary materially in credibility and may copy each other. How To Use It: Use Recorded Future as a deconfliction source; do not treat every sale post, repost, or public claim as equivalent proof of access, and do not republish raw marketplace artifacts.[34]
23-Jun-2026 · Added Sophos Firewall advisory boundary
Sophos says it received third-party information that the same threat actors targeted internet-exposed Sophos Firewall appliances, and its investigation framed the activity as user-level credential brute-forcing/stuffing rather than Sophos Firewall vulnerability exploitation.
Source Issue: 23-Jun-2026 · Added Sophos Firewall advisory boundary Agreement / Difference: Sophos says it received third-party information that the same threat actors targeted internet-exposed Sophos Firewall appliances, and its investigation framed the activity as user-level credential brute-forcing/stuffing rather than Sophos Firewall vulnerability exploitation. Tension or Contradiction: A Sophos Firewall/VPN scoping call can look FortiBleed-adjacent when valid credentials are involved, but the Sophos advisory does not prove a Sophos appliance compromise or a Sophos product vulnerability. How To Use It: Treat Sophos cases as adjacent edge-device credential-stuffing exposure until local Sophos Firewall logs, MFA evidence, VPN/admin portal telemetry, and successful-login records prove impact.[30]
Vulnerability vs credential framing
Fortinet says this is not a new Fortinet vulnerability and is not related to a recent incident or advisory, while some public reporting uses compromise, campaign, exploitation, or vulnerability-adjacent language.
Source Issue: Vulnerability vs credential framing Agreement / Difference: Fortinet says this is not a new Fortinet vulnerability and is not related to a recent incident or advisory, while some public reporting uses compromise, campaign, exploitation, or vulnerability-adjacent language. Tension or Contradiction: Headline language can imply a new bug or patch-only event even when the strongest vendor/government framing points to credential exposure and hardening. How To Use It: Let Fortinet and CISA control the vulnerability/remediation framing; use media phrasing only as public-risk context.[2] [3] [5] [13] [14]
Exposure vs confirmed access
Sources describe exposed usernames, emails, plaintext passwords in many cases, potentially working passwords, and operational infrastructure, but they do not provide a reliable public count of successful credential use or firewall changes.
Source Issue: Exposure vs confirmed access Agreement / Difference: Sources describe exposed usernames, emails, plaintext passwords in many cases, potentially working passwords, and operational infrastructure, but they do not provide a reliable public count of successful credential use or firewall changes. Tension or Contradiction: Credential presence creates urgent risk, but it does not automatically prove successful login, persistence, data access, or exfiltration. How To Use It: For scoping calls, separate dataset match, credential validity, successful login, persistence/configuration change, and confirmed impact.[4] [5] [8] [12] [15] [16]
Configuration-export uncertainty
Beaumont and Security Affairs add important context that the dataset may involve configuration-export material or credential-storage details rather than only intercepted login traffic.
Source Issue: Configuration-export uncertainty Agreement / Difference: Beaumont and Security Affairs add important context that the dataset may involve configuration-export material or credential-storage details rather than only intercepted login traffic. Tension or Contradiction: That raises the severity of scoping questions, but the public record does not prove the initial access method or a new Fortinet flaw. How To Use It: Use this as an investigation lead: check firmware state, admin logins, configuration export/change history, and credential-storage migration status.[15] [16]
Named-company evidence boundary
BleepingComputer, Hackread, and Security Affairs report named-company examples from screenshots or summaries. 27-Jul-2026 · Added CHT Security's first-party clarification demonstrates why public naming must be separated from actual organization impact: the company says its mention reflected partner-account product-registration/support context rather than internal compromise. 13-Aug-2026 · Added Roche's first-party advisory adds a separate customer-impact boundary: two Roche-associated FortiGate devices appeared in the dataset, but Roche found no evidence of impact to Roche customer Laboratory Networks.
Source Issue: Named-company evidence boundary Agreement / Difference: BleepingComputer, Hackread, and Security Affairs report named-company examples from screenshots or summaries. 27-Jul-2026 · Added CHT Security's first-party clarification demonstrates why public naming must be separated from actual organization impact: the company says its mention reflected partner-account product-registration/support context rather than internal compromise. 13-Aug-2026 · Added Roche's first-party advisory adds a separate customer-impact boundary: two Roche-associated FortiGate devices appeared in the dataset, but Roche found no evidence of impact to Roche customer Laboratory Networks. Tension or Contradiction: Public naming can be mistaken for confirmed victim compromise, while partner, reseller, support, registration, former-asset, or customer-managed relationships may explain some names without proving direct environment or customer impact. How To Use It: Use named organizations as private scoping and notification leads, not as proof of breach or successful access; prefer first-party disclosures when available.[4] [6] [16] [41] [43]
16-Aug-2026 · Added Regional CERT exposure scoping
BGD e-GOV CIRT says it identified 153 unique Bangladesh IP addresses associated with the FortiBleed tag and requiring investigation.
Source Issue: 16-Aug-2026 · Added Regional CERT exposure scoping Agreement / Difference: BGD e-GOV CIRT says it identified 153 unique Bangladesh IP addresses associated with the FortiBleed tag and requiring investigation. Tension or Contradiction: A regional IP-count advisory can be misread as a confirmed breach count, while the advisory is better treated as an exposure-validation and incident-response trigger. How To Use It: Use BGD e-GOV CIRT for Bangladesh-specific scoping and public-sector coordination; do not publish raw IPs or infer successful compromise for every tagged address.[44]
This card reconciles what the retained sources agree on, where they diverge, and which sources should control the brief when public reporting conflicts. Expansion Research Mode will be handled separately: any future AI-enhanced research notes should be visibly labeled, source-backed, and added to the citations card in a distinct enhanced-research citation group rather than blended into the baseline evidence.
About the Contributors
Fortinet PSIRT
Fortinet's official Product Security Incident Response Team responsible for vulnerability disclosures and advisories.
Contributor: Fortinet PSIRT Who They Are / What They Do: Fortinet's official Product Security Incident Response Team responsible for vulnerability disclosures and advisories. Contribution & Why It Matters Here: Official vendor response: Not a new Fortinet vulnerability; likely credential reuse and brute-force activity. Provides authoritative clarification on the nature of the exposure.[13]
CISA
U.S. Cybersecurity and Infrastructure Security Agency — leads national cyber defense, issues the KEV catalog, and publishes hardening guidance.
Contributor: CISA Who They Are / What They Do: U.S. Cybersecurity and Infrastructure Security Agency — leads national cyber defense, issues the KEV catalog, and publishes hardening guidance. Contribution & Why It Matters Here: Authoritative hardening guidance: Terminate SSL VPN/admin sessions, reset passwords, enable phishing-resistant MFA, and review logs. Sets official remediation priority.[14]
26-Aug-2026 · Added Canadian Centre for Cyber Security
Canada's national cyber security authority publishing public alerts, advisories, and reporting channels for Canadian organizations.
Contributor: 26-Aug-2026 · Added Canadian Centre for Cyber Security Who They Are / What They Do: Canada's national cyber security authority publishing public alerts, advisories, and reporting channels for Canadian organizations. Contribution & Why It Matters Here: Newly retained source, published more than 24 hours before this run: adds official Canadian FortiBleed guidance for account inventory, suspicious-account removal, management-interface restriction, session termination, password reset, MFA, firmware review, gateway defense, privilege-management, and reporting matching activity.[45]
Hudson Rock
Cyber intelligence and breach-notification platform specializing in credential-exposure lookup tools and victim notification workflows.
Contributor: Hudson Rock Who They Are / What They Do: Cyber intelligence and breach-notification platform specializing in credential-exposure lookup tools and victim notification workflows. Contribution & Why It Matters Here: Primary lookup/disclosure workflow for organizations checking domains against the FortiBleed dataset. Enables rapid self-assessment of exposure.[9] [10]
Volodymyr Bob Diachenko
Independent security researcher known for discovering exposed databases and public credential leaks.
Contributor: Volodymyr Bob Diachenko Who They Are / What They Do: Independent security researcher known for discovering exposed databases and public credential leaks. Contribution & Why It Matters Here: Researcher-origin LinkedIn signal with discovery timing, screenshot context, and affected-domain scale claims. Provides early discovery context and scale estimation.[11]
SOCRadar
Global cyber threat intelligence and attack surface management company.
Contributor: SOCRadar Who They Are / What They Do: Global cyber threat intelligence and attack surface management company. Contribution & Why It Matters Here: Primary security-company reporting on scale, operational infrastructure, and credential validation context. 22-Jun-2026 · Added Later SOCRadar reporting adds FortigateSniffer operation analysis, operation servers, harvest cycles, protocol coverage, and expanded target metrics. 27-Jun-2026 · Revised The public campaign card adds unique-device and organizational-domain metric labels for active-operation scoping. 30-Jun-2026 · Revised SOCRadar's June 29 update attributes FortiBleed to Lynx / INC. 20-Jul-2026 · Revised The checker page now shows July 20 freshness while retaining the same headline checker metrics. 2-Jul-2026 · Added The July 2 STRU update links FortiBleed infrastructure to INC/Lynx ransomware operations, reports confirmed admin/domain-compromise counts, and says at least 12 ransomware deployments stemmed from FortiBleed-derived access. 22-Jul-2026 · Added Newly retained; published >24h before this run: SOCRadar's public Volume II landing page adds high-level support for operator/hierarchy analysis, victim workflows, AI-assisted offensive operations, targeting analysis, ATT&CK mapping, and IoC availability.[12] [25] [27] [35] [36] [40]
Kevin Beaumont
Independent cybersecurity researcher and commentator often focused on ransomware, credential leaks, and attacker tradecraft.
Contributor: Kevin Beaumont Who They Are / What They Do: Independent cybersecurity researcher and commentator often focused on ransomware, credential leaks, and attacker tradecraft. Contribution & Why It Matters Here: Independent practitioner analysis on cracked admin passwords, configuration-export uncertainty, and Fortinet credential-storage implications. Adds technical depth and practical implications.[15]
BleepingComputer
Leading independent cybersecurity news site covering breaches, malware, and threat actor activity.
Contributor: BleepingComputer Who They Are / What They Do: Leading independent cybersecurity news site covering breaches, malware, and threat actor activity. Contribution & Why It Matters Here: Core corroboration for approximately 73,932 firewall URLs and exposed Fortinet/FortiGate VPN credential categories. 22-Jun-2026 · Added Also provides mainstream technical corroboration of the FortigateSniffer operation details.[4] [26]
Hackread
Cybersecurity news outlet focused on breaches, threat intelligence, and global cyber incidents.
Contributor: Hackread Who They Are / What They Do: Cybersecurity news outlet focused on breaches, threat intelligence, and global cyber incidents. Contribution & Why It Matters Here: Scoping value: affected-domain count, global scale, Hudson Rock attribution, and reported lookup portal. Helps quantify exposure and directs defenders to lookup tools.[6]
CSO Online
Enterprise-focused cybersecurity publication covering risk management and operational security.
Contributor: CSO Online Who They Are / What They Do: Enterprise-focused cybersecurity publication covering risk management and operational security. Contribution & Why It Matters Here: Operational-risk lead: persistent-access warning and SOCRadar-reported operational server with stolen passwords, tooling, automation, and victim list. Frames business and operational risk for leadership.[8]
Security Affairs
Cybersecurity news publication founded by Pierluigi Paganini covering hacking, breaches, threat intelligence, and security incidents.
Contributor: Security Affairs Who They Are / What They Do: Cybersecurity news publication founded by Pierluigi Paganini covering hacking, breaches, threat intelligence, and security incidents. Contribution & Why It Matters Here: Corroborating report tying together Diachenko, Beaumont, Hudson Rock, named-company examples, configuration-export concerns, Hashtopolis/45-GPU hash-cracking claims, and practical remediation steps. 22-Jun-2026 · Added Later coverage summarizes SOCRadar's FortigateSniffer operation details and expanded targeting metrics.[16] [28]
SpyCloud Labs
Identity-threat and cybercrime-intelligence research team focused on exposed credentials, malware, and criminal infrastructure.
Contributor: SpyCloud Labs Who They Are / What They Do: Identity-threat and cybercrime-intelligence research team focused on exposed credentials, malware, and criminal infrastructure. Contribution & Why It Matters Here: 23-Jun-2026 · Added Adds independent infrastructure analysis: campaign server roles, broader Synology/Sophos/MSSQL targeting, AI-assisted tooling, IAB-style monetization, and SantaAd forum signal.[29]
26-Jun-2026 · Added Recorded Future Insikt Group
Threat intelligence research team producing source-backed analysis of cybercrime infrastructure, actor claims, and credential-exposure activity.
Contributor: 26-Jun-2026 · Added Recorded Future Insikt Group Who They Are / What They Do: Threat intelligence research team producing source-backed analysis of cybercrime infrastructure, actor claims, and credential-exposure activity. Contribution & Why It Matters Here: Newly retained source, published more than 24 hours before this run: adds seller-credibility deconfliction, workflow corroboration, and caution around low-credibility copycat or re-extortion claims without requiring publication of raw infrastructure or victim artifacts. 5-Jul-2026 · Checked Manual revisit confirms the page should retain this source for behavior-level infrastructure/workflow scoping, not raw artifact publication.[34]
Sophos
Cybersecurity vendor and Sophos Firewall provider publishing product advisories and MDR/XDR guidance.
Contributor: Sophos Who They Are / What They Do: Cybersecurity vendor and Sophos Firewall provider publishing product advisories and MDR/XDR guidance. Contribution & Why It Matters Here: 23-Jun-2026 · Added Official adjacent advisory: same-threat-actor targeting of internet-exposed Sophos Firewall appliances, credential brute-forcing/stuffing against user-level accounts, MFA emphasis for Admin/User/VPN portals, and no observed Sophos Firewall vulnerability exploitation so far.[30]
16-Aug-2026 · Added BGD e-GOV CIRT
Bangladesh national computer incident response team publishing public advisories for local cyber-risk coordination.
Contributor: 16-Aug-2026 · Added BGD e-GOV CIRT Who They Are / What They Do: Bangladesh national computer incident response team publishing public advisories for local cyber-risk coordination. Contribution & Why It Matters Here: Newly retained source, published more than 24 hours before this run: adds Bangladesh-specific exposure scoping around 153 unique IP addresses associated with the FortiBleed tag, with investigation and credential-response guidance.[44]
CyberUnit
Cybersecurity research and media outlet covering threats, breaches, and defensive strategies.
Contributor: CyberUnit Who They Are / What They Do: Cybersecurity research and media outlet covering threats, breaches, and defensive strategies. Contribution & Why It Matters Here: Executive caveat framing: many plaintext passwords, 194-country scope, and no-new-CVE/no-zero-day caveat. Helps leadership understand the true nature and breadth of the exposure.[5]
ITKnowledgeBases
Technical knowledge base and guidance site for IT and security professionals.
Contributor: ITKnowledgeBases Who They Are / What They Do: Technical knowledge base and guidance site for IT and security professionals. Contribution & Why It Matters Here: Defender action framing: FortiGate SSL VPN and exposed administrative interfaces, credential rotation, MFA, access restriction, and log review. Provides practical, step-by-step remediation guidance.[3]
Real World Examples
Reported high-profile dataset entries
BleepingComputer reports screenshots and information shared by Diachenko included entries for Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, and others.
Example: Reported high-profile dataset entries Source-Backed Description: BleepingComputer reports screenshots and information shared by Diachenko included entries for Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, and others. What It Does / Does Not Prove: Suggests the dataset may include major organization identifiers; does not prove those organizations were breached or that listed credentials worked. Defender Use: Named entities should validate exposure privately through owned domains, credential-intelligence checks, and internal logs.[4]
Reported global company entries
Hackread and Security Affairs report names listed in exposed data include Samsung, Oracle, Foxconn, Comcast, Siemens, Lenovo, Spotify, Sony, PwC, Accenture, and others, according to Hudson Rock, screenshots, and related reporting.
Example: Reported global company entries Source-Backed Description: Hackread and Security Affairs report names listed in exposed data include Samsung, Oracle, Foxconn, Comcast, Siemens, Lenovo, Spotify, Sony, PwC, Accenture, and others, according to Hudson Rock, screenshots, and related reporting. What It Does / Does Not Prove: Dataset inclusion is not equivalent to confirmed compromise, successful access, or public victim confirmation. Defender Use: Organizations should perform domain, URL, and account-level scoping rather than relying on public name lists alone.[6] [16]
Hash-cracking and configuration-export reporting
Security Affairs reports claims that SSL VPN authentication hashes were intercepted and cracked using a 45-GPU Hashtopolis cluster, and that the data appeared to include configuration-export material rather than only intercepted login traffic.
Example: Hash-cracking and configuration-export reporting Source-Backed Description: Security Affairs reports claims that SSL VPN authentication hashes were intercepted and cracked using a 45-GPU Hashtopolis cluster, and that the data appeared to include configuration-export material rather than only intercepted login traffic. What It Does / Does Not Prove: Raises the scoping question of device/configuration access and credential-storage state; does not establish the initial access method or a new Fortinet vulnerability. Defender Use: Ask scoping teams to examine firmware state, admin login history, configuration export evidence, credential-storage upgrade status, and successful admin logins.[16]
Operational server lead
CSO Online reports SOCRadar independently discovered an operational server containing stolen FortiGate passwords, tools, automation infrastructure, a victim list, and attribution-relevant information.
Example: Operational server lead Source-Backed Description: CSO Online reports SOCRadar independently discovered an operational server containing stolen FortiGate passwords, tools, automation infrastructure, a victim list, and attribution-relevant information. What It Does / Does Not Prove: Suggests organized credential-compromise activity; does not provide retained IOCs, tool names, or actor attribution. Defender Use: Use as a reason to investigate successful logins, persistence, and configuration changes after exposure signals.[8]
22-Jun-2026 · Added SOCRadar active-operation victimology
SOCRadar describes more than 1,000 compromised victims across 120 countries, SMB-heavy exposure, and a sensitive defense-contractor example in its active-operation analysis.
Example: 22-Jun-2026 · Added SOCRadar active-operation victimology Source-Backed Description: SOCRadar describes more than 1,000 compromised victims across 120 countries, SMB-heavy exposure, and a sensitive defense-contractor example in its active-operation analysis. What It Does / Does Not Prove: Shows why this should be scoped as active credential-harvesting and possible initial-access risk; does not authorize publishing raw victim lists, credentials, or customer-identifying dataset rows. Defender Use: Use for urgency, portfolio cross-reference, and private validation against owned domains, Fortinet assets, and logs.[25] [27] [28]
23-Jun-2026 · Added SpyCloud access-broker infrastructure
SpyCloud describes brute-force, operator-workstation, and cracking infrastructure roles, broader non-Fortinet scanning, AI-assisted tooling, and a redacted sensitive exfiltration example tied to selective hands-on intrusion.
Example: 23-Jun-2026 · Added SpyCloud access-broker infrastructure Source-Backed Description: SpyCloud describes brute-force, operator-workstation, and cracking infrastructure roles, broader non-Fortinet scanning, AI-assisted tooling, and a redacted sensitive exfiltration example tied to selective hands-on intrusion. What It Does / Does Not Prove: Shows FortiBleed sits inside a broader access-broker operation; does not authorize publishing raw server, victim, credential, marketplace, or exfiltrated-file details. Defender Use: For confirmed exposure, widen scoping to AD, LDAP, Kerberos/NTLM, session replay, MSSQL, adjacent edge devices, and data-access review.[29]
24-Jun-2026 · Added Recovered FortiBleed toolchain analysis
Arctic Wolf reports reverse-engineering a recovered CyberStrike Harvester binary and tying it to credential stuffing, spraying, configuration harvesting, offline cracking, capture processing, AD/SMB tooling, and credential-cleaning workflows.
Example: 24-Jun-2026 · Added Recovered FortiBleed toolchain analysis Source-Backed Description: Arctic Wolf reports reverse-engineering a recovered CyberStrike Harvester binary and tying it to credential stuffing, spraying, configuration harvesting, offline cracking, capture processing, AD/SMB tooling, and credential-cleaning workflows. What It Does / Does Not Prove: Provides source-backed technical hunting leads; does not prove the same tool ran in every listed environment or justify publishing recovered artifacts. Defender Use: Use to scope FortiGate, AD/SMB, credential-cracking, and file-share activity after suspected access while withholding raw sensitive artifacts.[31]
23-Jun-2026 · Added Sophos Firewall credential-stuffing advisory
Sophos says the same threat actors targeted internet-exposed Sophos Firewall appliances through user-level credential brute-forcing/stuffing, especially where MFA was not present for Admin, User, or VPN portal access.
Example: 23-Jun-2026 · Added Sophos Firewall credential-stuffing advisory Source-Backed Description: Sophos says the same threat actors targeted internet-exposed Sophos Firewall appliances through user-level credential brute-forcing/stuffing, especially where MFA was not present for Admin, User, or VPN portal access. What It Does / Does Not Prove: Shows the actor pattern extends into adjacent edge-firewall credential targeting; it does not prove Sophos Firewall vulnerability exploitation or compromise in any given environment. Defender Use: For Sophos Firewall scoping calls, collect Sophos Firewall auth logs, portal exposure, MFA enrollment evidence, successful VPN/admin/user-portal events, and credential-reuse context before attributing impact.[30]
2-Jul-2026 · Added SOCRadar ransomware-link finding
SOCRadar says FortiBleed infrastructure is directly connected to INC Ransom and Lynx ransomware operations, with admin-level access confirmed on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments.
Example: 2-Jul-2026 · Added SOCRadar ransomware-link finding Source-Backed Description: SOCRadar says FortiBleed infrastructure is directly connected to INC Ransom and Lynx ransomware operations, with admin-level access confirmed on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments. What It Does / Does Not Prove: Shows an aggregate ransomware-impact path for FortiBleed-derived access; does not provide a public victim list or prove impact for every exposed FortiGate environment. Defender Use: Escalate confirmed FortiBleed exposure into AD/domain-controller review, ransomware deployment checks, endpoint encryption indicators, backup integrity validation, and legal/IR coordination.[36]
22-Jul-2026 · Added SOCRadar Volume II public landing page
SOCRadar's FortiBleed Unmasked Volume II page says the campaign connects harvested FortiGate credentials to Lynx and INC ransomware infrastructure and summarizes operator/hierarchy analysis, victim-management workflows, AI-assisted offensive operations, technical profiling, targeting analysis, ATT&CK mapping, and IoC availability.
Example: 22-Jul-2026 · Added SOCRadar Volume II public landing page Source-Backed Description: SOCRadar's FortiBleed Unmasked Volume II page says the campaign connects harvested FortiGate credentials to Lynx and INC ransomware infrastructure and summarizes operator/hierarchy analysis, victim-management workflows, AI-assisted offensive operations, technical profiling, targeting analysis, ATT&CK mapping, and IoC availability. What It Does / Does Not Prove: Strengthens source support for the operation-structure and AI-assisted-operation framing that was previously caveated as pending a public whitepaper; it does not make raw IoCs, victim details, recovered artifacts, or acquisition paths appropriate for this public brief. Defender Use: Use to update attribution and operation-structure caveats for private scoping, ransomware-readiness review, and ATT&CK-informed hunting while keeping sensitive artifacts out of the public page.[40]
27-Jul-2026 · Added CHT Security first-party clarification
CHT Security says its name appeared in recent FortiBleed intelligence reporting because its FortiSupport Partner account had been used for prior customer product-registration and technical-support workflows, and says its internal systems had no intrusion, data leak, or security impact.
Example: 27-Jul-2026 · Added CHT Security first-party clarification Source-Backed Description: CHT Security says its name appeared in recent FortiBleed intelligence reporting because its FortiSupport Partner account had been used for prior customer product-registration and technical-support workflows, and says its internal systems had no intrusion, data leak, or security impact. What It Does / Does Not Prove: Shows that a name in FortiBleed-related intelligence can reflect partner/support workflow context rather than direct organization compromise; does not prove whether any customer device or credential was exposed. Defender Use: Use first-party statements to qualify named-list handling, notification prioritization, and public-impact language. Keep customer, account, device, and dataset details private unless a direct disclosure supports them.[41]
13-Aug-2026 · Added Roche first-party customer-impact boundary
Roche says its investigation identified two Roche-associated FortiGate devices in the FortiBleed dataset, with one tied to a non-Diagnostics business unit and one appearing to be a former Roche device reused by a customer; Roche found no evidence of impact to Roche customer Laboratory Networks.
Example: 13-Aug-2026 · Added Roche first-party customer-impact boundary Source-Backed Description: Roche says its investigation identified two Roche-associated FortiGate devices in the FortiBleed dataset, with one tied to a non-Diagnostics business unit and one appearing to be a former Roche device reused by a customer; Roche found no evidence of impact to Roche customer Laboratory Networks. What It Does / Does Not Prove: Shows why dataset inclusion can require asset-lineage and customer-impact validation before public victim conclusions; does not prove broader Roche compromise or customer compromise. Defender Use: Use first-party disclosures to separate associated assets, former assets, customer-managed devices, and actual customer impact. Keep device identifiers, credentials, and dataset details private unless directly disclosed.[43]
6-Jul-2026 · Added UK public-sector account reporting
The Times and The Sun report a FortiBleed-linked stolen-login cluster affecting UK Foreign Office and local-government account examples; The Sun says NCSC issued an urgent Fortinet brute-force alert and advised organizations to review networks and isolate compromised devices.
Example: 6-Jul-2026 · Added UK public-sector account reporting Source-Backed Description: The Times and The Sun report a FortiBleed-linked stolen-login cluster affecting UK Foreign Office and local-government account examples; The Sun says NCSC issued an urgent Fortinet brute-force alert and advised organizations to review networks and isolate compromised devices. What It Does / Does Not Prove: Adds public-sector exposure context and alert urgency; does not prove every named organization suffered successful intrusion, persistence, data theft, or ransomware impact. Defender Use: Use for public-sector, critical-infrastructure, and third-party-provider scoping; withhold raw account lists, credentials, dataset rows, and sensitive organization-specific details. Apply NCSC guidance as official response context, not as confirmation of every media-reported account example.[37] [38] [39]
Public Victims / Disclosure Matrix
Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, Oracle, Siemens, Lenovo, Spotify, Sony, PwC, Accenture, and others
Unconfirmed; reported dataset/name examples
Victim / Group: Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, Oracle, Siemens, Lenovo, Spotify, Sony, PwC, Accenture, and others Confirmation Status: Unconfirmed; reported dataset/name examples Reported Or Disclosed By: BleepingComputer, Hackread, and Security Affairs report or summarize named-company examples from screenshots, Hudson Rock context, or related reporting; this brief treats those names as private scoping leads, not as proof that working credentials were used, systems were changed, or data was stolen.[4] [6] [16]
22-Jun-2026 · Added SOCRadar aggregate victim population
Aggregate victimology; not a publishable named-victim list
Victim / Group: 22-Jun-2026 · Added SOCRadar aggregate victim population Confirmation Status: Aggregate victimology; not a publishable named-victim list Reported Or Disclosed By: SOCRadar and related summaries describe more than 1,000 compromised victims across 120 countries, SMB-heavy exposure, and a sensitive defense-contractor example; later SOCRadar campaign-card metrics add 80,553 unique devices and 23,406 organizational domains. Use this as scoping priority, not public naming.[25] [27] [28] [35]
2-Jul-2026 · Added SOCRadar aggregate ransomware-impact finding
Aggregate impact finding; not a publishable named-victim list
Victim / Group: 2-Jul-2026 · Added SOCRadar aggregate ransomware-impact finding Confirmation Status: Aggregate impact finding; not a publishable named-victim list Reported Or Disclosed By: SOCRadar reports admin-level access on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments tied to FortiBleed-derived access. Use as escalation evidence for confirmed exposure; do not infer ransomware impact for an organization without local telemetry and do not publish victim identifiers.[36]
6-Jul-2026 · Added UK Foreign Office and local-government account examples
Reported public-sector exposure cluster; first-party impact not confirmed in this brief
Victim / Group: 6-Jul-2026 · Added UK Foreign Office and local-government account examples Confirmation Status: Reported public-sector exposure cluster; first-party impact not confirmed in this brief Reported Or Disclosed By: July 5 UK reporting says a FortiBleed-linked stolen-login cluster included UK Foreign Office overseas and local-government staff examples and references NCSC Fortinet brute-force alerting. This brief retains the reporting as public-sector scoping context only; it does not publish raw credentials, account lists, or organization-specific impact conclusions.[37] [38]
27-Jul-2026 · Added CHT Security named-list clarification
First-party no-internal-impact statement; customer exposure not publicly enumerated
Victim / Group: 27-Jul-2026 · Added CHT Security named-list clarification Confirmation Status: First-party no-internal-impact statement; customer exposure not publicly enumerated Reported Or Disclosed By: CHT Security says its FortiBleed mention came from prior customer Fortinet product-registration and support use of its FortiSupport Partner account, and that it found no internal intrusion, data leak, or security impact. Treat this as a confirmed clarification, not as a confirmed FortiBleed compromise or public customer list.[41]
13-Aug-2026 · Added Roche Diagnostics customer-impact boundary
First-party associated-device statement; no customer-impact evidence found
Victim / Group: 13-Aug-2026 · Added Roche Diagnostics customer-impact boundary Confirmation Status: First-party associated-device statement; no customer-impact evidence found Reported Or Disclosed By: Roche says two Roche-associated FortiGate devices appeared in the FortiBleed dataset, but its review found no evidence of impact to Roche customer Laboratory Networks. Treat this as a first-party deconfliction example: associated, former, or customer-reused assets still need asset-lineage validation before public victim-impact language is used.[43]
16-Aug-2026 · Added Bangladesh FortiBleed-tagged IP exposure set
Regional CERT exposure-scoping count; not confirmed breach count
Victim / Group: 16-Aug-2026 · Added Bangladesh FortiBleed-tagged IP exposure set Confirmation Status: Regional CERT exposure-scoping count; not confirmed breach count Reported Or Disclosed By: BGD e-GOV CIRT says it identified 153 unique Bangladesh IP addresses associated with the FortiBleed tag and requiring investigation. Treat this as a national-CIRT scoping signal for asset owners and responders; do not publish raw IPs or describe all tagged addresses as confirmed intrusions.[44]
Organizations matching Hudson Rock or SOCRadar lookup workflows
Potentially exposed; owner validation required
Victim / Group: Organizations matching Hudson Rock or SOCRadar lookup workflows Confirmation Status: Potentially exposed; owner validation required Reported Or Disclosed By: Hudson Rock provides a FortiBleed domain lookup, and SOCRadar provides a FortiBleed Check workflow for domain, IP, or CIDR review. A positive lookup is an exposure signal requiring tenant, device, and log validation; a negative lookup is not proof of absence.[10] [27]
Huntress partner organizations identified through private corpus matching
Privately identified; not publicly named here
Victim / Group: Huntress partner organizations identified through private corpus matching Confirmation Status: Privately identified; not publicly named here Reported Or Disclosed By: Huntress reports cross-referencing listed IP addresses against its own corpus and identifying affected partner organizations. That is a model for private notification and scoping, not permission to publish customer names, credentials, IPs, or complete match results.[17]
27-Jun-2026 · Added This is not a raw public victim list. PANDA separates reported exposure examples, aggregate victimology, private lookup matches, and confirmed victim disclosures. A name below should be treated as confirmed only when the classification says so; otherwise it is a scoping lead that requires owned-domain, Fortinet/FortiGate asset, credential-intelligence, active-session, and log validation before impact language is used. Raw leaked domains, firewall URLs, credentials, hashes, IPs, and sensitive dataset rows remain out of scope for publication. 16-Aug-2026 · Revised BGD e-GOV CIRT's 153-IP Bangladesh exposure count is retained as a regional scoping signal, not as a confirmed breach count or public victim list. 27-Jul-2026 · Revised The retained public source set now includes one first-party clarification from a named organization: CHT Security says its FortiBleed mention reflected partner-account registration/support context and not internal compromise, data leakage, or security impact. That supports caution around named-list interpretation; it does not create a public customer-victim list.[4] [6] [10] [16] [41] [44]
KEV and CVE Details
CISA KEV listing
No KEV entry is supported by retained evidence; CISA issued a hardening alert rather than a KEV listing.
Item: CISA KEV listing Status: No KEV entry is supported by retained evidence; CISA issued a hardening alert rather than a KEV listing. Why It Matters: Do not claim KEV status for FortiBleed from this record.[14]
FortiBleed CVE
Fortinet states the activity is not a new Fortinet vulnerability; Canadian Cyber Centre references older Fortinet CVEs for firmware review but does not identify FortiBleed as a new CVE.
Item: FortiBleed CVE Status: Fortinet states the activity is not a new Fortinet vulnerability; Canadian Cyber Centre references older Fortinet CVEs for firmware review but does not identify FortiBleed as a new CVE. Why It Matters: Response should not wait for CVE publication, and older Fortinet CVE patch review should run alongside credential/session response.[13] [45]
Confirmed Fortinet zero-day
Fortinet says the activity is not related to any recent incident or advisory.
Item: Confirmed Fortinet zero-day Status: Fortinet says the activity is not related to any recent incident or advisory. Why It Matters: Treat as credential exposure and possible credential abuse unless new evidence changes the assessment.[13]
Patch-only remediation
CISA's actions focus on sessions, passwords, MFA, and logs; Fortinet frames weak credential hygiene as central; Canadian Cyber Centre adds account inventory, suspicious-account removal, access restriction, and firmware review.
Item: Patch-only remediation Status: CISA's actions focus on sessions, passwords, MFA, and logs; Fortinet frames weak credential hygiene as central; Canadian Cyber Centre adds account inventory, suspicious-account removal, access restriction, and firmware review. Why It Matters: Credential rotation, MFA, access restriction, log review, account review, and firmware validation are central.[13] [14] [45]
MITRE ATT&CK Lifecycle Mapping
Reconnaissance
Dataset reporting ties records to Fortinet/FortiGate firewall or SSL VPN URLs, affected domains, and business-intelligence fields such as industry, revenue, employee count, and country.
MITRE ATT&CK Tactic: Reconnaissance Evidence / Behavior: Dataset reporting ties records to Fortinet/FortiGate firewall or SSL VPN URLs, affected domains, and business-intelligence fields such as industry, revenue, employee count, and country. Defensive Breakpoint: Map public Fortinet URLs and owned domains to actual assets and owners before impact statements.[4] [5] [6] [9] [10] [16]
Open sourceResource Development
The reported dataset appears organized for downstream use, with business-context fields and target comments described as resembling an access-sales catalog. 23-Jun-2026 · Added SpyCloud adds IAB-style infrastructure, AI-assisted tooling, and SantaAd marketplace signal. 24-Jun-2026 · Added Arctic Wolf adds recovered-tooling context around CyberStrike Harvester, FortiGate Sniffer references, AD/SMB tooling, and cracking workflows.
MITRE ATT&CK Tactic: Resource Development Evidence / Behavior: The reported dataset appears organized for downstream use, with business-context fields and target comments described as resembling an access-sales catalog. 23-Jun-2026 · Added SpyCloud adds IAB-style infrastructure, AI-assisted tooling, and SantaAd marketplace signal. 24-Jun-2026 · Added Arctic Wolf adds recovered-tooling context around CyberStrike Harvester, FortiGate Sniffer references, AD/SMB tooling, and cracking workflows. Defensive Breakpoint: Treat public naming, revenue/industry fields, forum references, tool names, and domain lists as scoping leads; do not publish them as proof of victim compromise.[16] [29] [31]
Open sourceCredential Access
Reports describe a server, list, or dataset containing Fortinet/FortiGate credentials, including usernames, emails, plaintext passwords in many cases, possible configuration-export material, and cracked or potentially working passwords.
MITRE ATT&CK Tactic: Credential Access Evidence / Behavior: Reports describe a server, list, or dataset containing Fortinet/FortiGate credentials, including usernames, emails, plaintext passwords in many cases, possible configuration-export material, and cracked or potentially working passwords. Defensive Breakpoint: Terminate active sessions, rotate affected credentials, investigate reuse, and review password-storage and firmware state.[4] [5] [8] [14] [15] [16]
Open sourceCredential Access
22-Jun-2026 · Added SOCRadar and BleepingComputer describe FortigateSniffer using FortiOS packet-capture functionality to collect traffic and feed credentials or hashes into parsing, cracking, and replay workflows. 24-Jun-2026 · Added Arctic Wolf adds post-authentication capture-processing and recovered-binary context.
MITRE ATT&CK Tactic: Credential Access Evidence / Behavior: 22-Jun-2026 · Added SOCRadar and BleepingComputer describe FortigateSniffer using FortiOS packet-capture functionality to collect traffic and feed credentials or hashes into parsing, cracking, and replay workflows. 24-Jun-2026 · Added Arctic Wolf adds post-authentication capture-processing and recovered-binary context. Defensive Breakpoint: Review FortiGate admin command use, diagnose sniffer packet activity, PCAP exports, SSH/admin access, and protocol traffic during suspected capture windows.[25] [26] [28] [31]
Open sourceInitial Access
Stolen or valid FortiGate credentials could enable VPN or administrative access if still active and not protected by MFA.
MITRE ATT&CK Tactic: Initial Access Evidence / Behavior: Stolen or valid FortiGate credentials could enable VPN or administrative access if still active and not protected by MFA. Defensive Breakpoint: Enforce phishing-resistant MFA, restrict public management interfaces, invalidate exposed credentials, and review successful VPN/admin logins.[13] [14] [16] [45]
Open sourcePersistence / Privilege Escalation
Reporting warns that attackers with firewall access could change settings, create backdoor admin accounts, and maintain access; CSO Online and SOCRadar also describe operational infrastructure with tools, automation, and a victim list. 7-Aug-2026 · Revised CybelAngel adds planted Fortinet-service-like administrator account names for local review. 26-Aug-2026 · Revised Canada's Cyber Centre independently flags suspicious account examples including forticloud-sync and forticloud-tech.
MITRE ATT&CK Tactic: Persistence / Privilege Escalation Evidence / Behavior: Reporting warns that attackers with firewall access could change settings, create backdoor admin accounts, and maintain access; CSO Online and SOCRadar also describe operational infrastructure with tools, automation, and a victim list. 7-Aug-2026 · Revised CybelAngel adds planted Fortinet-service-like administrator account names for local review. 26-Aug-2026 · Revised Canada's Cyber Centre independently flags suspicious account examples including forticloud-sync and forticloud-tech. Defensive Breakpoint: Review admin account creation, privilege changes, configuration changes, policy changes, service-like account names, and long-lived VPN sessions.[8] [12] [16] [42] [45]
Open sourceCollection / Exfiltration / Impact
Retained sources discuss alleged downstream compromise in public reporting. 23-Jun-2026 · Added SpyCloud adds a redacted sensitive exfiltration example, but that should remain a private validation lead rather than a reusable victim narrative.
MITRE ATT&CK Tactic: Collection / Exfiltration / Impact Evidence / Behavior: Retained sources discuss alleged downstream compromise in public reporting. 23-Jun-2026 · Added SpyCloud adds a redacted sensitive exfiltration example, but that should remain a private validation lead rather than a reusable victim narrative. Defensive Breakpoint: Separate dataset inclusion from credential validity, successful login, persistence, collection, exfiltration, and confirmed business impact in legal and executive reporting.[4] [6] [8] [16] [29]
Open sourceFramework note: this section uses MITRE ATT&CK Enterprise Tactics terminology. MITRE defines tactics as the adversary's tactical goals; the row-level citations below source the FortiBleed-specific evidence and caveats.
Source Weighting / Relevance
CISA
Very High
Source: CISA Weight: Very High Relevance: Authoritative response guidance Key Supported Points: Terminate SSL VPN/admin sessions, reset VPN/admin passwords, enable phishing-resistant MFA, and review logs after credential exposure reports. Limitations: Does not prove successful compromise at every listed organization.
Fortinet PSIRT
Very High
Source: Fortinet PSIRT Weight: Very High Relevance: Official vendor position Key Supported Points: Not a new Fortinet vulnerability, not related to a recent incident/advisory, and likely involving credential reuse plus brute-force activity. Limitations: Vendor position does not replace local scoping or prove absence of compromise.
Hudson Rock
High
Source: Hudson Rock Weight: High Relevance: Primary dataset and lookup workflow Key Supported Points: FortiBleed branding, ethical-disclosure workflow, and domain lookup path. Limitations: Organization-specific results must be validated with internal asset/account telemetry.
SOCRadar
High
Source: SOCRadar Weight: High Relevance: Primary operational-infrastructure analysis Key Supported Points: 29-Jun-2026 · Revised Reported operational infrastructure, credential validation, expanded scale context, FortigateSniffer tooling, protocol harvesting, operation servers, harvest cycles, exposure-check workflow, 59.3M scanned hosts, 80,553 unique devices, and 23,406 organizational domains. 30-Jun-2026 · Revised Freshly reported (<24h): SOCRadar attributes FortiBleed to Lynx / INC. 20-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows July 20 freshness and says new compromised devices are being added while retaining the same headline checker metrics. 2-Jul-2026 · Added Freshly reported (<24h): SOCRadar links FortiBleed infrastructure to INC/Lynx ransomware operations, reports 200+ additional operational servers, admin-level access on 409 targets, full domain compromise on 354, and at least 12 ransomware deployments. 22-Jul-2026 · Added Newly retained; published >24h before this run: SOCRadar's public Volume II landing page adds high-level operator/hierarchy, victim-workflow, AI-assisted-operation, targeting-analysis, ATT&CK-mapping, and IoC-availability support. Limitations: Must be reconciled with Fortinet, CISA, and NCSC framing before making incident-impact claims; newer active-operation metrics are not interchangeable with earlier URL-count metrics, and actor/ransomware attribution should remain source-caveated until corroborated by local or additional primary evidence. Do not republish raw IoCs, infrastructure, victim details, recovered artifacts, credentials, or acquisition paths.
UK NCSC
Very High
Source: UK NCSC Weight: Very High Relevance: Official UK response guidance Key Supported Points: 7-Jul-2026 · Added Newly retained; published >24h before this run. Supports UK-focused FortiBleed checker validation, IoC review, isolation where compromise evidence exists, factory-reset escalation where persistence may exist, shared-credential scoping, management-interface hardening, MFA, and PBKDF2 enforcement. Limitations: Does not validate raw media-reported account lists or prove successful compromise at every listed organization; use as official response context.
Canadian Centre for Cyber Security
Very High
Source: Canadian Centre for Cyber Security Weight: Very High Relevance: Official Canadian response guidance Key Supported Points: 26-Aug-2026 · Added Newly retained; published >24h before this run. Supports Canadian FortiBleed scoping and response: account inventory, suspicious-account removal, management-interface restriction, session termination, password resets, MFA, firmware review, internet-gateway defense, privilege-management, and Cyber Centre reporting for matching activity. Limitations: Does not add a new victim list, credential dataset, compromise count, or FortiBleed CVE; use as official regional hardening and reporting guidance.
CHT Security
High
Source: CHT Security Weight: High Relevance: First-party named-list deconfliction Key Supported Points: 27-Jul-2026 · Added Newly retained; published >24h before this run. Supports the boundary that a FortiBleed intelligence mention may reflect partner-account product-registration/support relationships rather than direct organization compromise, and records CHT Security's no-internal-intrusion, no-data-leak, and no-security-impact statement. Limitations: Does not enumerate customer devices, credentials, domains, or exposure results; do not infer customer compromise or absence of customer exposure from this statement alone.
Roche Diagnostics
High
Source: Roche Diagnostics Weight: High Relevance: First-party customer-impact deconfliction Key Supported Points: 13-Aug-2026 · Added Newly retained; published >24h before this run. Supports associated-device and customer-impact boundary handling: Roche says two Roche-associated FortiGate devices appeared in the FortiBleed dataset, but its investigation found no evidence of impact to Roche customer Laboratory Networks. Limitations: Does not disclose raw device identifiers, credentials, domains, or dataset rows; do not infer broader Roche compromise, customer compromise, or universal non-impact from this statement alone.
BGD e-GOV CIRT
High
Source: BGD e-GOV CIRT Weight: High Relevance: Regional CERT exposure scoping Key Supported Points: 16-Aug-2026 · Added Newly retained; published >24h before this run. Supports Bangladesh-specific exposure validation: BGD e-GOV CIRT identifies 153 unique Bangladesh IP addresses associated with the FortiBleed tag and recommends credential rotation, log review, and investigation. Limitations: Do not publish raw addresses, treat the 153-IP figure as confirmed compromises, or let regional scoping override Fortinet/CISA/NCSC official vulnerability-status and hardening language.
CybelAngel REACT
High
Source: CybelAngel REACT Weight: High Relevance: Persistence-review and attribution corroboration Key Supported Points: 7-Aug-2026 · Added Newly retained; published >24h before this run. Adds planted Fortinet-service-like administrator account names and public SantaAd attribution based on CybelAngel's analysis of exposed campaign material. Limitations: Do not republish raw infrastructure, victim rows, credentials, or sensitive dataset files; use account names as local hunt terms and keep attribution source-caveated.
The Times / The Sun
Medium-High
Source: The Times / The Sun Weight: Medium-High Relevance: Fresh UK public-sector reporting Key Supported Points: 6-Jul-2026 · Added Freshly reported (<24h): UK reporting adds Foreign Office and local-government account examples, NCSC Fortinet brute-force alerting context, and a roughly 80,000-account reporting cluster. This is useful for public-sector, critical-infrastructure, and provider scoping urgency. Limitations: Media reporting rather than first-party organizational telemetry; do not publish raw account lists, credentials, sensitive dataset rows, or confirmed-impact claims from this source cluster alone.
SpyCloud Labs
High
Source: SpyCloud Labs Weight: High Relevance: Infrastructure and access-broker analysis Key Supported Points: 23-Jun-2026 · Added Multi-server campaign roles, broader Synology/Sophos/MSSQL targeting, AI-assisted tooling, IAB-style monetization, SantaAd forum signal, and redacted sensitive exfiltration evidence. Limitations: Do not republish raw server identifiers, forum artifacts, victim details, credentials, or sensitive exfiltration descriptions; use for scoping and tradecraft only.
Recorded Future Insikt Group
High
Source: Recorded Future Insikt Group Weight: High Relevance: Marketplace and infrastructure claim deconfliction Key Supported Points: 26-Jun-2026 · Added Newly retained source, published more than 24 hours before this run. Adds likely-credible SantaAd assessment, low-credibility copycat/re-extortion warning, FortiBleed workflow context, and caution around public sale claims. 5-Jul-2026 · Checked Manual revisit preserves behavior-level workflow and infrastructure scoping value without adding raw artifacts. Limitations: Do not republish raw infrastructure, recovered artifacts, forum images, credentials, victim names, or acquisition instructions; use to qualify claims and guide private validation.
Sophos
High
Source: Sophos Weight: High Relevance: Official adjacent Sophos Firewall advisory Key Supported Points: 23-Jun-2026 · Added Same-threat-actor targeting of internet-exposed Sophos Firewall appliances, user-level credential brute-forcing/stuffing, MFA-lacking target context, no Sophos compromise observed so far, and no Sophos Firewall vulnerability exploitation observed so far. Limitations: Does not prove every Sophos VPN credential-stuffing case is FortiBleed, and does not replace local Sophos Firewall, IdP, VPN, and MFA telemetry.
Arctic Wolf
High
Source: Arctic Wolf Weight: High Relevance: Reverse-engineering and toolchain analysis Key Supported Points: 24-Jun-2026 · Added Recovered CyberStrike Harvester binary analysis, FortiGate Sniffer panel references, credential stuffing/spraying, configuration harvesting, offline cracking, post-authentication capture processing, AD/SMB tooling, credential cleaners, and low-confidence Russian-speaking operator indicators. Limitations: Do not republish raw recovered artifacts, hashes, infrastructure, victim paths, credentials, or sensitive exfiltration details; keep attribution low confidence.
Unit 42
Medium-High
Source: Unit 42 Weight: Medium-High Relevance: Vendor telemetry and defensive pattern Key Supported Points: 27-Jun-2026 · Revised Published-date metadata corrected to June 26, 2026. Supports suspicious login attempts in Unit 42 customer telemetry, MSSQL targeting, curated password-list spraying, possible configuration extraction, offline cracking, unvalidated forum-sale claims, and an explicit Unit 42 caveat that the activity was not targeting Palo Alto Networks devices. Limitations: Not Fortinet/CISA official guidance; forum-sale claims are explicitly unvalidated by Unit 42, and the telemetry note should not be restated as Palo Alto Networks device exploitation.
SANS NewsBites
Medium-High
Source: SANS NewsBites Weight: Medium-High Relevance: Practitioner incident-response guidance Key Supported Points: 24-Jun-2026 · Added Perimeter-device playbook guidance: consider traffic visible to a compromised firewall, check for backdoors, enforce MFA, restrict management interfaces, and consider device replacement for severe suspected compromise. Limitations: Editorial/practitioner synthesis, not primary Fortinet telemetry or a government advisory.
Kevin Beaumont / DoublePulsar
High
Source: Kevin Beaumont / DoublePulsar Weight: High Relevance: Independent practitioner validation and caveat framing Key Supported Points: Cracked admin password framing, configuration-export uncertainty, and Fortinet credential-storage implications. Limitations: Practitioner analysis; not a vendor advisory or government alert.
BleepingComputer
High
Source: BleepingComputer Weight: High Relevance: Core public corroboration Key Supported Points: 73,932 firewall URLs; Fortinet/FortiGate VPN credentials; usernames, emails, plaintext passwords; Bob Diachenko discovery. 22-Jun-2026 · Added June 22 coverage adds a FortigateSniffer summary of SOCRadar findings. Limitations: Does not prove all credentials work or that each URL is a unique device; newer FortigateSniffer article is primarily corroboration of SOCRadar's deeper technical analysis.
CyberUnit
High
Source: CyberUnit Weight: High Relevance: Caveat and executive framing Key Supported Points: 73,932 firewall/SSL VPN URLs; 194 countries; plaintext passwords in many cases; no new CVE, no zero-day, no single patch. Limitations: Secondary reporting; primary Hudson Rock methodology not retained.
Hackread
High
Source: Hackread Weight: High Relevance: Scoping utility Key Supported Points: 73,932 URLs; 21,632 affected domains; 194 countries; Hudson Rock lookup portal; Bob Diachenko attribution. Limitations: Portal URL, data freshness, and validation method are not retained.
Security Affairs
Medium-High
Source: Security Affairs Weight: Medium-High Relevance: Corroboration and scoping depth Key Supported Points: Named-company examples, Diachenko/Beaumont/Hudson Rock linkage, configuration-export discussion, 45-GPU Hashtopolis hash-cracking claim, and remediation summary. 22-Jun-2026 · Added June 22 coverage adds synthesis of FortigateSniffer operation details. Limitations: Secondary reporting; use alongside primary Hudson Rock, Beaumont, SOCRadar, Fortinet, and CISA sources.
ITKnowledgeBases
Medium-High
Source: ITKnowledgeBases Weight: Medium-High Relevance: Defender actions and caveats Key Supported Points: Not a CVE; not a confirmed zero-day; FortiGate SSL VPN and exposed admin interfaces; rotate credentials, enforce MFA, restrict access, review logs. Limitations: Article title mentions CVEs, but retained body does not support specific CVE claims.
CSO Online
Medium-High
Source: CSO Online Weight: Medium-High Relevance: Operational-risk lead Key Supported Points: Persistent-access warning; potentially working password list; SOCRadar operational server with passwords, tools, automation infrastructure, and victim list. Limitations: Use alongside SOCRadar primary reporting; no retained actor attribution is available.
Additional IntelliOS Threat Intel Products on This Topic
Flash Threat Intel Brief
Current FortiBleed product of record. Version v4.5 includes the AI monitoring update, FortigateSniffer scoping context, and revised exposure/hunting guidance.
One-Page Cheat Sheet
Use this companion page for Sophos Firewall scoping: internet-exposed Admin/User/VPN portals, MFA enrollment, credential-stuffing evidence, and the boundary that Sophos has not observed Sophos Firewall vulnerability exploitation.
Notes
Create an account and sign-in to use this card.
Record your personal notes and comments in this card related to this brief.
Version Change Log
v1.0
19-Jun-2026
Version: v1.0 Date: 19-Jun-2026 Release Type: Initial publication What Changed: Published the baseline FortiBleed Flash Threat Intel Brief with exposure framing, source coverage, CISA/Fortinet response guidance, IOCs/observables, talking points, MITRE mapping, source reconciliation, and citations.[4] [9] [10] [13] [14]
v1.1
22-Jun-2026
Version: v1.1 Date: 22-Jun-2026 Release Type: AI monitoring update What Changed: Added the first AI Agent delta update: newer SOCRadar/BleepingComputer reporting, FortigateSniffer and protocol-harvesting context, operation-server and harvest-cycle metrics, and expanded active-operation hunting guidance.[25] [26] [27] [28]
v1.2
23-Jun-2026
Version: v1.2 Date: 23-Jun-2026 Release Type: Revision and polish pass What Changed: Added visible brief-version metadata, tightened delta badges, standardized update labels, added username-pattern scoping signals, and refined executive, technical, glossary, and response language around current public evidence.[12] [25] [29]
v1.3
23-Jun-2026
Version: v1.3 Date: 23-Jun-2026 Release Type: AI monitoring update What Changed: Added Sophos advisory delta: adjacent Sophos Firewall credential brute-force/stuffing targeting, MFA portal scope, no observed Sophos Firewall compromise or vulnerability exploitation so far, and a companion Sophos one-page cheat sheet.[30]
v1.4
23-Jun-2026
Version: v1.4 Date: 23-Jun-2026 Release Type: Presentation update What Changed: Prominently highlighted the SOCRadar FortiBleed Check free security tool, direct lookup URL, screenshot, accepted domain/IP/CIDR input types, and scoping caveat.[27]
v1.5
24-Jun-2026
Version: v1.5 Date: 24-Jun-2026 Release Type: AI monitoring update What Changed: Added Arctic Wolf reverse-engineering delta for CyberStrike Harvester and associated FortiBleed toolchain, added SANS corroboration, revised the SOCRadar checker timestamp, and tightened behavior-level observables without publishing raw sensitive artifacts.[27] [31] [33]
v1.6
24-Jun-2026
Version: v1.6 Date: 24-Jun-2026 Release Type: Structural cleanup What Changed: Moved the FortigateSniffer technical Q&A out of the TTPs card into a dedicated Common Questions Q&A card and renumbered downstream sections for cleaner navigation. Source / Basis: Internal presentation cleanup
v1.6
25-Jun-2026 8:02 AM ET
Version: v1.6 Date: 25-Jun-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content update was identified, and the product version was not incremented. Updated audit trail, metadata modified timestamp, and PANDA index checked timestamp only. Source / Basis: Source check: Fortinet PSIRT, CISA, SOCRadar, BleepingComputer, Hudson Rock, Field Effect, Bitdefender, The Hacker News, SC Media, ZenoX, Security Affairs, WaterISAC, Diachenko/Kevin Beaumont
v1.7
26-Jun-2026 8:03 AM ET
Version: v1.7 Date: 26-Jun-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed June 26 monitor delta: SOCRadar checker freshness revised to June 26 with unchanged headline metrics; Recorded Future/Insikt newly retained as a published-before-run source for marketplace/seller credibility deconfliction and copycat/re-extortion caveats. Updated AI Agent Delta Updates, BLUF, source reconciliation, social signal, contributor notes, source weighting, citations, metadata, and PANDA index dates.[27] [34]
v1.8
27-Jun-2026 8:03 AM ET
Version: v1.8 Date: 27-Jun-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed June 27 monitor delta: SOCRadar checker freshness revised to June 27; SOCRadar Campaigns newly retained for active-operation metric vocabulary including 80,553 unique devices and 23,406 organizational domains; Unit 42 publication date corrected to June 26. Updated AI Agent Delta Updates, BLUF, exposure snapshot, source reconciliation, contributor notes, source weighting, citations, metadata, and PANDA index dates.[27] [32] [35]
v1.9
27-Jun-2026 3:57 PM ET
Version: v1.9 Date: 27-Jun-2026 3:57 PM ET Release Type: Manual product update What Changed: Added Public Victims / Disclosure Matrix as card 23, separated public dataset/name examples from confirmed victim disclosures, added private lookup and portfolio-matching guidance, renumbered downstream cards, and updated the side-panel card menu.[4] [6] [10] [16] [17] [25] [27] [35]
v1.9
28-Jun-2026 8:02 AM ET
Version: v1.9 Date: 28-Jun-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content update was identified, and the product version was not incremented. Updated audit trail, metadata modified timestamp, and PANDA index date only. Source / Basis: Source check: Fortinet PSIRT, CISA, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Bitdefender, The Hacker News, CSA Singapore, IANS
v2.0
29-Jun-2026 8:04 AM ET
Version: v2.0 Date: 29-Jun-2026 8:04 AM ET Release Type: AI monitoring update What Changed: Added source-backed June 29 monitor delta: SOCRadar FortiBleed Check freshness revised to June 29 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus a newly retained 59.3M scanned-host active-operation metric. Updated AI Agent Delta Updates, BLUF, exposure snapshot, source reconciliation, source weighting, citations, metadata, and PANDA index dates.[27]
v2.1
30-Jun-2026 8:03 AM ET
Version: v2.1 Date: 30-Jun-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed June 30 monitor delta: SOCRadar's June 29 9:00 AM EST update attributes FortiBleed to Lynx / INC and says a full technical report is forthcoming. Updated AI Agent Delta Updates, BLUF, executive summary, threat actor glossary, source reconciliation, contributor notes, source weighting, citations, metadata, and PANDA index dates. Picus and other newly observed June 30 summaries were not retained because they duplicated already represented claims.[12]
v2.2
1-Jul-2026 8:03 AM ET
Version: v2.2 Date: 1-Jul-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 1 monitor delta: SOCRadar FortiBleed Check freshness revised to July 1 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus a continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, executive summary, source reconciliation, contributor notes, source weighting, citations, metadata, and PANDA index dates. Older or newly observed CSA, Huntress, CISA, Fortinet PSIRT, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Beaumont, Arctic Wolf, Sophos, and SpyCloud items were duplicative, already represented, unsupported, or unsuitable for publication.[27]
v2.3
2-Jul-2026 8:03 AM ET
Version: v2.3 Date: 2-Jul-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 2 monitor delta: SOCRadar STRU linked FortiBleed infrastructure to INC Ransom and Lynx ransomware operations, added aggregate admin-access, full-domain-compromise, ransomware-deployment, operational-server, and operator-structure findings, and retained publication boundaries for raw indicators, operator aliases, infrastructure, victim details, and technical artifacts. Updated AI Agent Delta Updates, BLUF, executive summary, timeline, term glossary, TTPs, threat actor glossary, source reconciliation, contributor notes, real world examples, public victim/disclosure matrix, source weighting, citations, metadata, and PANDA index dates.[36]
v2.4
3-Jul-2026 8:03 AM ET
Version: v2.4 Date: 3-Jul-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 3 monitor delta: SOCRadar FortiBleed Check freshness revised to July 2 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Newly observed July 2-July 3 media and ISAC summaries duplicated the SOCRadar July 2 STRU ransomware-link findings already represented in v2.3, so they were not retained as additional citations. Updated AI Agent Delta Updates, BLUF, executive summary, source reconciliation, source weighting, citations, metadata, and PANDA index dates.[27]
v2.4
4-Jul-2026 8:02 AM ET
Version: v2.4 Date: 4-Jul-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content update was identified, and the product version was not incremented. Newly observed Dataprise July 4 reporting duplicated already represented official and SOCRadar framing; older marketplace summaries were duplicative or unsuitable for public publication. Updated audit trail, metadata modified timestamp, and PANDA index date only. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Dataprise, Picus, Bitdefender, The Hacker News, CSA, eSentire, S-RM
v2.5
5-Jul-2026 8:01 AM ET
Version: v2.5 Date: 5-Jul-2026 8:01 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 5 monitor delta: SOCRadar FortiBleed Check freshness revised to July 5 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Newly observed July 4-July 5 summaries duplicated already represented official, SOCRadar, and media framing, so they were not retained as additional citations. Updated AI Agent Delta Updates, BLUF, executive summary, source reconciliation, source weighting, citations, metadata, and PANDA index dates.[27]
v2.5
5-Jul-2026 5:43 PM ET
Version: v2.5 Date: 5-Jul-2026 5:43 PM ET Release Type: Manual source check (no version increment) What Changed: User-supplied Recorded Future/Insikt FortiBleed report was checked and confirmed already retained as citation 34 from v1.7. Clarified BLUF, source reconciliation, contributor, source weighting, citations, and AI Agent Delta Updates language so the report is visibly used for behavior-level workflow and infrastructure scoping while raw infrastructure, artifacts, victim references, credentials, and acquisition paths remain unpublished.[34]
v2.6
6-Jul-2026 8:55 AM ET
Version: v2.6 Date: 6-Jul-2026 8:55 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 6 monitor delta: freshly reported July 5 UK reporting from The Times and The Sun adds UK Foreign Office and local-government account examples, NCSC Fortinet brute-force alerting context, and a roughly 80,000-account reporting cluster. Updated AI Agent Delta Updates, BLUF, Executive Summary, Timeline, IOCs / Observables, Real World Examples, Public Victims / Disclosure Matrix, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Duplicate SOCRadar/INC/Lynx summaries and SEO rewrites were not retained as additional citations; raw account lists, credentials, sensitive dataset rows, and organization-specific impact claims remain unpublished.[37] [38]
v2.7
7-Jul-2026 8:02 AM ET
Version: v2.7 Date: 7-Jul-2026 8:02 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 7 monitor delta: SOCRadar FortiBleed Check freshness revised to July 7 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Newly retained UK NCSC's June 18 alert as an official published-before-run source for UK checker validation, IoC review, isolation/factory-reset escalation, shared-credential scoping, management-interface hardening, MFA, and PBKDF2 enforcement. Updated AI Agent Delta Updates, BLUF, Executive Summary, Timeline, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Duplicate UK syndication, older summaries, unsupported claims, members-only/TLP-limited WaterISAC/DHS references, and SEO rewrites were not retained as additional citations.[27] [39]
v2.8
8-Jul-2026 8:03 AM ET
Version: v2.8 Date: 8-Jul-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 8 monitor delta: SOCRadar FortiBleed Check freshness revised to July 8 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 7-July 8 items were checker freshness, duplicate SOCRadar ransomware-link recaps, UK follow-on reporting already represented by retained sources, older summaries, unsupported claims, blocked pages, or SEO rewrites and were not retained as additional citations.[27]
v2.9
9-Jul-2026 8:01 AM ET
Version: v2.9 Date: 9-Jul-2026 8:01 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 9 monitor delta: indexed public SOCRadar FortiBleed Check content freshness revised to July 9 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 8-July 9 items were checker freshness, duplicate recaps, videos/social posts, older summaries, unsupported claims, blocked pages, or SEO rewrites and were not retained as additional citations.[27]
v2.9
10-Jul-2026 8:03 AM ET
Version: v2.9 Date: 10-Jul-2026 8:03 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content update was identified, and the product version was not incremented. SOCRadar FortiBleed Check remained last updated July 9, 2026 with unchanged headline metrics. Newly observed July 9-July 10 items were secondary recaps, link collections, older vendor summaries, blocked or member-only pages, social/video posts, unrelated Fortinet PSIRT items, or SEO rewrites already represented by retained sources. Updated audit trail, metadata modified timestamp, and PANDA index date only. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Qualys, ITPro, SC Media, SecurityWeek, The Hacker News, The Times, The Sun
v3.0
11-Jul-2026 8:00 AM ET
Version: v3.0 Date: 11-Jul-2026 8:00 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 11 monitor delta: SOCRadar FortiBleed Check freshness revised to July 11 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 10-July 11 items were checker freshness, older secondary summaries, blocked or member-only pages, unrelated Fortinet PSIRT items, or duplicate recaps already represented by retained sources and were not retained as additional citations.[27]
v3.1
12-Jul-2026 8:03 AM ET
Version: v3.1 Date: 12-Jul-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 12 monitor delta: SOCRadar FortiBleed Check freshness revised to July 12 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 11-July 12 items were checker freshness, social/video posts, older secondary summaries, blocked pages, unrelated Fortinet PSIRT items, or duplicate recaps already represented by retained sources and were not retained as additional citations.[27]
v3.2
13-Jul-2026 8:02 AM ET
Version: v3.2 Date: 13-Jul-2026 8:02 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 13 monitor delta: SOCRadar FortiBleed Check freshness revised to July 13 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 12-July 13 items were checker freshness, older or already represented summaries, unrelated Fortinet PSIRT items, blocked/social/video pages, or duplicate recaps already represented by retained sources and were not retained as additional citations.[27]
v3.3
14-Jul-2026 8:02 AM ET
Version: v3.3 Date: 14-Jul-2026 8:02 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 14 monitor delta: SOCRadar FortiBleed Check freshness revised to July 14 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 13-July 14 items were checker freshness, older Hudson Rock/InfoStealers detail already represented by retained sources, unrelated Fortinet PSIRT items, blocked/social pages, or duplicate recaps already represented by retained sources and were not retained as additional citations.[27]
v3.4
15-Jul-2026 8:02 AM ET
Version: v3.4 Date: 15-Jul-2026 8:02 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 15 monitor delta: SOCRadar FortiBleed Check freshness revised to July 15 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 14-July 15 items were checker freshness, older or already represented summaries, unrelated Fortinet PSIRT items, blocked/member-only/social pages, or duplicate recaps already represented by retained sources and were not retained as additional citations.[27]
v3.5
16-Jul-2026 8:02 AM ET
Version: v3.5 Date: 16-Jul-2026 8:02 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 16 monitor delta: SOCRadar FortiBleed Check freshness revised to July 16 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 15-July 16 items were checker freshness, already represented SOCRadar/Risky Business AI-enabled-operation commentary, older or duplicate summaries, social/video posts, or unverifiable claims not retained as additional citations.[27]
v3.6
17-Jul-2026 8:03 AM ET
Version: v3.6 Date: 17-Jul-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 17 monitor delta: SOCRadar FortiBleed Check freshness revised to July 17 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 16-July 17 items were checker freshness, already represented official guidance, older or duplicate summaries, blocked pages, or unsupported claims not retained as additional citations.[27]
v3.7
18-Jul-2026 8:03 AM ET
Version: v3.7 Date: 18-Jul-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 18 monitor delta: SOCRadar FortiBleed Check freshness revised to July 18 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 17-July 18 items were checker freshness, FortiBleed-as-comparator edge-infrastructure commentary, already represented official guidance, older or duplicate summaries, blocked pages, or unsupported claims not retained as additional citations. No external email, subscriber alert, or notification was sent under the automation no-email policy.[27]
v3.8
19-Jul-2026 8:02 AM ET
Version: v3.8 Date: 19-Jul-2026 8:02 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 19 monitor delta: SOCRadar FortiBleed Check freshness revised to July 19 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 18-July 19 items were checker freshness, already represented official guidance, older or duplicate summaries, unrelated Fortinet vulnerability advisories, blocked pages, or unsupported claims not retained as additional citations. No external email, subscriber alert, or notification was sent under the automation no-email policy.[27]
v3.9
20-Jul-2026 8:03 AM ET
Version: v3.9 Date: 20-Jul-2026 8:03 AM ET Release Type: AI monitoring update What Changed: Added source-backed July 20 monitor delta: SOCRadar FortiBleed Check freshness revised to July 20 with unchanged 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics, plus the continued statement that new compromised devices are being added. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, Source Weighting, Citations, metadata, and PANDA index dates. Newly observed July 19-July 20 items were checker freshness, already represented official guidance, older or duplicate summaries, unrelated Fortinet vulnerability advisories, blocked pages, or unsupported claims not retained as additional citations. No external email, subscriber alert, or notification was sent under the automation no-email policy.[27]
v3.9
21-Jul-2026 8:01 AM ET
Version: v3.9 Date: 21-Jul-2026 8:01 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content update was identified, and the product version was not incremented. SOCRadar FortiBleed Check did not show a verifiable July 21 checker update in retrieved page text and retained already represented headline metrics. Newly observed July 20-July 21 items were duplicate recaps, older summaries, search-index freshness without page-backed changed findings, unrelated Fortinet vulnerability material, blocked/social pages, or unsupported claims. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, or notification was sent under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, Singapore CSA, ASD ACSC, SOCRadar, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, WaterISAC, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, IndustrialCyber, Cloud Security Alliance, SecurityWeek, The Hacker News, Arete, Bitdefender
v4.0
22-Jul-2026 8:04 AM ET
Version: v4.0 Date: 22-Jul-2026 8:04 AM ET Release Type: AI monitoring update What Changed: Added one newly retained source-backed delta: SOCRadar's public FortiBleed Unmasked Volume II landing page, with exact landing-page publication timestamp unavailable but public references observed July 6, 2026, more than 24 hours before this run. Updated AI Agent Delta Updates, BLUF, Executive Summary, Source Reconciliation, About the Contributors, Real World Examples, Threat Actor Glossary, Source Weighting, Citations, metadata, and PANDA index dates. Retained only high-level operator/hierarchy, victim-workflow, AI-assisted-operation, targeting-analysis, ATT&CK-mapping, and IoC-availability framing; raw IoCs, victim details, infrastructure, recovered artifacts, credentials, and acquisition paths remain unpublished. No external email, subscriber alert, or notification was sent under the automation no-email policy.[40]
v4.0
23-Jul-2026 8:03 AM ET
Version: v4.0 Date: 23-Jul-2026 8:03 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content update was identified, and the product version was not incremented. Newly observed July 22-July 23 items were crawled-today older reporting, unrelated security news, duplicate SOCRadar/BleepingComputer/Unit 42/Risky Business context already represented, SEO rewrites, social posts, or unsupported claims. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, or notification was sent under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, IndustrialCyber, Cloud Security Alliance, Risky Business, Bitsight, Security Boulevard, and related public reporting
v4.0
24-Jul-2026 8:01 AM ET
Version: v4.0 Date: 24-Jul-2026 8:01 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content update was identified, and the product version was not incremented. Newly observed July 23-July 24 items were broader VPN/ransomware context, crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/Recorded Future context already represented, SEO rewrites, social posts, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 24 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, or notification was sent under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, IndustrialCyber, Cloud Security Alliance, Bitsight, Bitdefender, and related public reporting
v4.0
25-Jul-2026 8:00 AM ET
Version: v4.0 Date: 25-Jul-2026 8:00 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content update was identified, and the product version was not incremented. Newly observed July 24-July 25 items were broader VPN/ransomware context, older regional CERT/media reporting, crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/Recorded Future context already represented, SEO rewrites, social posts, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 25 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, or notification was sent under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, IndustrialCyber, Cloud Security Alliance, Bitsight, Bitdefender, Shadowserver, Business Recorder/Pakistan National CERT reporting, and related public reporting
v4.0
26-Jul-2026 8:03 AM ET
Version: v4.0 Date: 26-Jul-2026 8:03 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed content update was identified, and the product version was not incremented. Newly observed July 25-July 26 items were crawled-today older reporting, SMB-oriented Fortinet July patch/FortiBleed recap content, duplicate SOCRadar/Fortinet/CISA/Unit 42/Hudson Rock/BleepingComputer context already represented, SEO rewrites, social posts, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 26 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, or notification was sent under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, IndustrialCyber, Cloud Security Alliance, Bitsight, Bitdefender, Shadowserver, Business Recorder/Pakistan National CERT reporting, Preferred Data, Penligent, The Hacker News, Dark Reading, and related public reporting
v4.1
27-Jul-2026 8:02 AM ET
Version: v4.1 Date: 27-Jul-2026 8:02 AM ET Release Type: AI monitoring update What Changed: Added one source-backed deconfliction delta: CHT Security's July 25 first-party clarification, newly retained as published more than 24 hours before this run, says its FortiBleed mention reflected FortiSupport Partner account product-registration/support context rather than CHT Security internal compromise, data leakage, or security impact. Fresh July 27 Taiwan media coverage repeated the clarification and was treated as duplicate amplification, while CybersecurityNews July 27 edge-VPN reporting duplicated existing remote-access/ransomware context. Updated AI Agent Delta Updates, BLUF, Real World Examples, Public Victims / Disclosure Matrix, Source Weighting, Citations, metadata, and PANDA index dates. No external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy.[41]
v4.1
06-Aug-2026 8:04 AM ET
Version: v4.1 Date: 06-Aug-2026 8:04 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 5-August 6 items were Fortinet corporate/product/security pages unrelated to FortiBleed findings, SOCRadar webinar/event listings and IOC/free-tool navigation that did not add retained technical findings, crawled-today duplicate June/July FortiBleed reporting, DataBreachToday/BankInfoSecurity and Cybersecurity Dive duplicates of already represented July 2 SOCRadar Lynx/INC linkage, CybersecurityNews and SecurityOnline pages with current site dates but June publication dates, duplicate Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CSO Online, IndustrialCyber, ITPro, social/video posts, search-index-only pages, and related public reporting
v4.2
07-Aug-2026 8:02 AM ET
Version: v4.2 Date: 07-Aug-2026 8:02 AM ET Release Type: AI monitoring update What Changed: Added one newly retained source-backed delta: CybelAngel's June 25 public flash-report summary, newly retained as published more than 24 hours before this run, adds planted Fortinet-service-like administrator account names for persistence review and supports source-caveated SantaAd attribution. Duplicate August 6-August 7 summaries, search-index freshness without page-backed FortiBleed changes, unrelated Fortinet/company/security pages, FortiBleed-as-comparator items, social/video posts, SEO rewrites, and unsupported CVE/attribution claims were not retained. Updated AI Agent Delta Updates, BLUF, Timeline, Response Playbook, IOCs / Observables, Threat Actor Glossary, Source Weighting, Citations, metadata, and PANDA index dates. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.[42]
v4.3
13-Aug-2026 8:12 AM ET
Version: v4.3 Date: 13-Aug-2026 8:12 AM ET Release Type: AI monitoring update What Changed: Added one newly retained source-backed deconfliction delta: Roche Diagnostics' June 30 first-party advisory, newly retained as published more than 24 hours before this run, says two Roche-associated FortiGate devices appeared in the FortiBleed dataset while Roche found no evidence of impact to Roche customer Laboratory Networks. CERT-In current-activity content dated June 18 duplicated existing government-warning and hardening context; Site24x7 trust-center text was newly observed but not retained because it lacked a verifiable FortiBleed publication/update timestamp; Cybernews/Gunra reporting was unrelated Fortinet CVE/ransomware context with FortiBleed only as background. Updated AI Agent Delta Updates, BLUF, Timeline, Source Reconciliation, Real World Examples, Public Victims / Disclosure Matrix, Source Weighting, Citations, metadata, and PANDA index dates. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.[43]
v4.4
16-Aug-2026 8:08 AM ET
Version: v4.4 Date: 16-Aug-2026 8:08 AM ET Release Type: AI monitoring update What Changed: Added one newly retained source-backed regional-CERT delta: BGD e-GOV CIRT's July 7 advisory, newly retained as published more than 24 hours before this run, identifies 153 unique Bangladesh IP addresses associated with the FortiBleed tag and requiring investigation. Newly observed August 15-August 16 items were mostly unrelated Fortinet/company/security news, current-site-date wrappers around older FortiBleed reporting, FortiBleed-as-comparator content, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel/Picus context, vendor/product pages, social amplification, SEO rewrites, or unsupported claims. Updated AI Agent Delta Updates, BLUF, Source Reconciliation, Public Victims / Disclosure Matrix, Source Weighting, About the Contributors, Citations, metadata, and PANDA index dates. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.[44]
v4.4
17-Aug-2026 8:07 AM ET
Version: v4.4 Date: 17-Aug-2026 8:07 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 16-August 17 items were unrelated Fortinet/company/security news, SOCRadar navigation or ransomware-profile pages that used FortiBleed only as a site/nav/comparator signal, older June/July FortiBleed reporting recrawled today, duplicate BGD e-GOV CIRT Bangladesh scoping recaps, duplicate Hudson Rock/InfoStealers republishing, current-site-date wrappers around older reporting, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 17 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, TAKA Alliance Bangladesh recap, Memeburn, CyberNexora, search-index-only pages, social/video posts, and related public reporting
v4.4
18-Aug-2026 8:02 AM ET
Version: v4.4 Date: 18-Aug-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 17-August 18 items were unrelated Fortinet/company/security news, government-site footer or recrawl freshness without new FortiBleed findings, older June/July FortiBleed reporting recrawled today, domain-specific lookup-result snippets unsuitable for publication, FortiBleed-as-comparator material, duplicate SOCRadar/Hudson Rock/BleepingComputer/CSA/CERT-In/Arete ransomware-link context already represented by retained sources, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 18 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. Subscriber all-check recipient count was queried, but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, TAKA Alliance Bangladesh recap, Arete, SecurityWeek, S-RM, ResearchGate/BrightTALK webinar references, search-index-only pages, social/video posts, and related public reporting
v4.4
19-Aug-2026 8:01 AM ET
Version: v4.4 Date: 19-Aug-2026 8:01 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 18-August 19 items were unrelated Fortinet/frontier-AI or security-news pages, webinar listings, current-site-date wrappers around older FortiBleed reporting, older June/July FortiBleed reporting recrawled today, FortiBleed-as-comparator material, duplicate SOCRadar/Hudson Rock/BleepingComputer/CSA/CERT-In/Arete ransomware-link context already represented by retained sources, duplicate regional government/social advisories, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 19 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. Subscriber count was unavailable in the local environment, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, TAKA Alliance Bangladesh recap, Arete, SecurityWeek, S-RM, Censys, CERT-PH/DICT social advisory snippets, ResearchGate/BrightTALK/Zscaler webinar references, search-index-only pages, social/video posts, and related public reporting
v4.4
20-Aug-2026 8:13 AM ET
Version: v4.4 Date: 20-Aug-2026 8:13 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 19-August 20 items were unrelated Fortinet/frontier-AI or security-news pages, webinar listings, current-site-date wrappers around older FortiBleed reporting, older June/July FortiBleed reporting recrawled today, FortiBleed-as-comparator material, duplicate SOCRadar/Hudson Rock/BleepingComputer/CSA/CERT-In/Arete/ZenoX/CybersecurityNews ransomware-link or FortigateSniffer context already represented by retained sources, duplicate regional government/social advisories, social amplification, SEO rewrites, or unsupported claims. Unit 42's August 18 update added TheHatman credential-attack content and product-protection guidance but did not revise the already retained FortiBleed-specific section; CERT-In's page footer showed Last Updated On August 20, 2026 while the FortiBleed activity remained dated June 18. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 20 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. Subscriber count query was blocked by missing local Supabase service credentials, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, search-index-only pages, social/video posts, and related public reporting
v4.4
21-Aug-2026 8:02 AM ET
Version: v4.4 Date: 21-Aug-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 20-August 21 items were unrelated Fortinet or security-news pages, current-site-date wrappers around older FortiBleed reporting, older June/July FortiBleed reporting recrawled today, FortiBleed-as-comparator material, duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources, social amplification, SEO rewrites, or unsupported claims. Unit 42's August 18 update remained a TheHatman/product-protection addition and did not revise the already retained FortiBleed-specific section. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 21 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. Subscriber count query was blocked by missing local Supabase service credentials, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, CERT-In, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting
v4.4
22-Aug-2026 8:02 AM ET
Version: v4.4 Date: 22-Aug-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 21-August 22 items were unrelated Fortinet, Cisco, GitLab, OpenAI, and security-news pages; current-site-date wrappers around older FortiBleed reporting; older June/July/August FortiBleed reporting recrawled today; FortiBleed-as-comparator material; duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources; social amplification; SEO rewrites; or unsupported claims. CERT-In's page footer showed Last Updated On August 22, 2026 while the FortiBleed activity remained dated June 18, 2026. Unit 42's August 18 update remained a TheHatman/product-protection addition and did not revise the already retained FortiBleed-specific section. The420's August 13 story and Provintell's August 22 index wrapper duplicated already represented reporting without stronger primary evidence. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 22 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. Active subscriber count was queried with 2 active subscribers and 1 all-check subscriber, but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Provintell/CODERED index material, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting
v4.4
23-Aug-2026 8:07 AM ET
Version: v4.4 Date: 23-Aug-2026 8:07 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 22-August 23 items were unrelated security-news pages; current-site-date wrappers around older FortiBleed reporting; older June/July/August FortiBleed reporting recrawled today; FortiBleed-as-comparator material; duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources; social amplification; SEO rewrites; or unsupported claims. CERT-In search snippets showed Last Updated On August 23, 2026 while the accessible FortiBleed-specific activity remained unavailable or dated June 18, 2026. Unit 42's August 18 update remained a TheHatman/product-protection addition and did not revise the already retained FortiBleed-specific section. The420's August 13 story duplicated already represented reporting without stronger primary evidence. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 23 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. Subscriber count query was blocked by missing local Supabase URL/service-role credentials, and no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Provintell/CODERED index material, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting
v4.4
24-Aug-2026 8:08 AM ET
Version: v4.4 Date: 24-Aug-2026 8:08 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 23-August 24 items were unrelated Fortinet or security-news pages; webinar listings without new public FortiBleed findings; current-site-date wrappers around older FortiBleed reporting; older June/July/August FortiBleed reporting recrawled today; FortiBleed-as-comparator material; SOCRadar ransomware-intelligence pages where FortiBleed appeared as navigation/tool chrome rather than a FortiBleed update; duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources; social amplification; SEO rewrites; or unsupported FortiBleed-to-CVE conflation. Fortinet's public blog index still showed the June 19 PSIRT FortiBleed analysis as the newest PSIRT FortiBleed-specific item. Unit 42's August 18 update remained a TheHatman/product-protection addition and did not revise the already retained FortiBleed-specific section. Tesorion's August 19 roundup pointed back to already represented SOCRadar, Fortinet, and SANS material. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 24 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. Active subscriber count was queried with 2 active subscribers and 1 all-check subscriber, but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Tesorion, BrightTalk/SOCRadar webinar listings, Techjack, Orca, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting
v4.4
25-Aug-2026 8:03 AM ET
Version: v4.4 Date: 25-Aug-2026 8:03 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 24-August 25 items were unrelated security-news or Fortinet-adjacent pages; FortiBleed event/webinar listings without new public findings; current-site-date wrappers around older FortiBleed reporting; older June/July/August FortiBleed reporting recrawled today; duplicate SOCRadar/Hudson Rock/BleepingComputer/CISA/WaterISAC/Bitdefender/Trend Micro/Sophos/Picus/CSA/Unit 42 context already represented by retained sources; FortiBleed-as-comparator material; social amplification; SEO rewrites; or unsupported FortiBleed-to-CVE conflation. Fortinet public pages did not surface a newer FortiBleed-specific PSIRT update, CISA/NICCS did not add a FortiBleed-specific advisory, Unit 42's August 18 update remained a broader credential-attack/product-protection addition without a new FortiBleed finding, and SOCRadar FortiBleed Check retained already represented headline metrics without a verifiable August 25 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. Active subscriber count was queried with 2 active subscribers and 1 all-check subscriber, but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer reporting, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, ZenoX, CybersecurityNews, GBHackers, The420, Tesorion, BrightTalk/SOCRadar webinar listings, Techjack, Orca, Fortinet FortiGuard pages, search-index-only pages, social/video posts, and related public reporting
v4.5
26-Aug-2026 8:02 AM ET
Version: v4.5 Date: 26-Aug-2026 8:02 AM ET Release Type: AI monitoring update What Changed: Added source-backed August 26 monitor delta: Canadian Centre for Cyber Security alert AL26-014 newly retained as an official Canadian government response-guidance source. Freshness label: newly retained; published >24h before this run. The alert supports Fortinet account inventory, suspicious-account removal, management-interface restriction, session termination, password reset, MFA, firmware review, internet-gateway defense, privilege-management, and reporting matching activity through Cyber Centre channels. Updated AI Agent Delta Updates, BLUF, Executive Summary, Timeline, CVE / Vulnerability References, Common Questions Q&A, Talking Points, MITRE ATT&CK Lifecycle Mapping, Tier 0 Through Tier 8 Source Summary, Source Reconciliation, About the Contributors, Source Weighting, Citations, metadata, home monitor status, and PANDA index dates. Newly observed August 25-August 26 items not retained were event listings, current-site-date wrappers, recrawled older FortiBleed reporting, duplicate source context, FortiBleed-as-comparator material, SEO rewrites, or unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented metrics and did not show a verifiable August 26 checker update timestamp in retrieved page text. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, and 1 all-check subscriber, but no external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy.[45]
v4.5
02-Sep-2026 8:12 AM ET
Version: v4.5 Date: 02-Sep-2026 8:12 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified after the September 1 monitor run, and the product version was not incremented. Newly observed September 1-September 2 items were unrelated Fortinet corporate or product-security pages, event/webinar and category wrappers around older FortiBleed reporting, current-site-date wrappers around June/July FortiBleed content, the August 31 MINE2 vendor-analysis post that restated already retained Unit 42/Recorded Future/Fortinet/SOCRadar/SecurityWeek claims and added product-specific deception recommendations not retained as FortiBleed source evidence, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Picus/Huntress/CSA/UpGuard/eSentire context already represented or previously rejected, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. Fortinet's public PSIRT article remained dated June 19, 2026; CISA's public FortiBleed alert remained June 2026; BleepingComputer's latest FortiBleed tag entries remained June 22 and July 1 reporting; SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable September 2 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. No newly added source was retained; freshness labels applied to retained sources: none. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, 1 no-change/all-check eligible subscriber, and 1 Slack-enabled subscriber. No external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, HKCERT, Nigeria CERT, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, marketing, and IOC Radar/navigation pages, BleepingComputer FortiBleed, FortigateSniffer, and Fortinet reporting/tag pages, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, UpGuard, eSentire, MINE2, CERT-PH/DICT social advisory snippets, search-index-only pages, social/video posts, and related public reporting
v4.5
01-Sep-2026 8:06 AM ET
Version: v4.5 Date: 01-Sep-2026 8:06 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified after the August 31 monitor run, and the product version was not incremented. Newly observed August 31-September 1 items were unrelated Fortinet stock/company or security-news pages, product-release wrappers around older FortiBleed reporting, current-site-date wrappers around June/July FortiBleed content, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Picus/Huntress/CSA/UpGuard context already represented or previously rejected, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. Fortinet's public PSIRT article remained dated June 19, 2026; CISA's public FortiBleed alert remained June 2026; BleepingComputer's latest FortiBleed tag entries remained June 22 and July 1 reporting; UpGuard's June 25 product-release note added no material public finding beyond existing scoping guidance. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. No newly added source was retained; freshness labels applied to retained sources: none. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, 1 no-change/all-check eligible subscriber, and 1 Slack-enabled subscriber. No external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, HKCERT, Nigeria CERT, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, marketing, and IOC Radar/navigation pages, BleepingComputer FortiBleed, FortigateSniffer, and Fortinet reporting/tag pages, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, UpGuard, CERT-PH/DICT social advisory snippets, search-index-only pages, social/video posts, and related public reporting
v4.5
31-Aug-2026 8:03 AM ET
Version: v4.5 Date: 31-Aug-2026 8:03 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 30-August 31 items were current-site-date wrappers around older June FortiBleed reporting, Fortinet event/corporate pages unrelated to FortiBleed, SOCRadar ransomware-intelligence and navigation pages where FortiBleed appeared as site chrome, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/HKCERT/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. Fortinet's public PSIRT article remained dated June 19, 2026; CISA's alert remained dated June 18, 2026 with a June 22, 2026 search-display date; Security Affairs' August 31 page elements were site furniture around a June 20 FortiBleed article; HKCERT and Nigeria CERT advisories were older regional guidance; and SOCRadar FortiBleed Check retained already represented headline metrics without a verifiable August 31 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. No newly added source was retained; freshness labels applied to retained sources: none. Active subscriber count was queried with 0 active subscribers, 0 email-enabled subscribers, 0 Slack-enabled subscribers, and 0 no-change/all-check eligible subscribers. No external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, HKCERT, Nigeria CERT, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, marketing, and IOC Radar/navigation pages, BleepingComputer FortiBleed and FortigateSniffer reporting/tag pages, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, Fortinet late-August blog/news items, search-index-only pages, social/video posts, and related public reporting
v4.5
30-Aug-2026 8:01 AM ET
Version: v4.5 Date: 30-Aug-2026 8:01 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 29-August 30 items were Fortinet corporate/product/security pages unrelated to FortiBleed, SOCRadar blog or navigation pages with already represented June/July FortiBleed metrics, BleepingComputer Fortinet tag entries whose newest FortiBleed-specific items remained the July 1 ransomware-link story and older June reporting, Unit 42's August 18 TheHatman addition that did not revise its already retained FortiBleed-specific section, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 30 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. No newly added source was retained; freshness labels applied to retained sources: none. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, 1 no-change/all-check eligible subscriber, and 1 Slack-enabled subscriber, but no external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, marketing, and IOC Radar/navigation pages, BleepingComputer FortiBleed and FortigateSniffer reporting/tag pages, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, Fortinet late-August blog/news items, search-index-only pages, social/video posts, and related public reporting
v4.5
27-Aug-2026 8:02 AM ET
Version: v4.5 Date: 27-Aug-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 26-August 27 items were Fortinet corporate or product-security posts unrelated to FortiBleed, SOCRadar navigation/IOC Radar pages where FortiBleed appeared only in site chrome, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 27 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. No newly added source was retained; freshness labels applied to retained sources: none. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, and 1 no-change/all-check eligible subscriber, but no external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, marketing, and IOC Radar/navigation pages, BleepingComputer FortiBleed and FortigateSniffer reporting/tag pages, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, Fortinet August blog/news items, search-index-only pages, social/video posts, and related public reporting
v4.5
29-Aug-2026 8:04 AM ET
Version: v4.5 Date: 29-Aug-2026 8:04 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 28-August 29 items were Fortinet corporate/public-private-partnership or deployment-guide pages unrelated to FortiBleed, CERT-In site-footer freshness around the unchanged June 18 FortiBleed current-activity entry, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. No newly added source was retained; freshness labels applied to retained sources: none. Active subscriber count was queried with 2 active subscribers, 2 email-enabled subscribers, 1 no-change/all-check eligible subscriber, and 1 Slack-enabled subscriber, but no external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, Slack alert, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, marketing, and IOC Radar/navigation pages, BleepingComputer FortiBleed and FortigateSniffer reporting/tag pages, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, Fortinet August blog/news items, search-index-only pages, social/video posts, and related public reporting
v4.5
28-Aug-2026 8:02 AM ET
Version: v4.5 Date: 28-Aug-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 27-August 28 items were Fortinet corporate, partner, or product-security pages unrelated to FortiBleed, recrawled older June/July/August FortiBleed reporting, duplicate SOCRadar/Hudson Rock/BleepingComputer/Fortinet/CISA/NCSC/Canada Cyber Centre/WaterISAC/Recorded Future/Unit 42/Bitdefender/Trend Micro/Picus/Huntress context already represented by retained sources or prior delta notes, FortiBleed-as-comparator material, social amplification, SEO rewrites, or unsupported CVE/FortiBleed conflation. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 28 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, home monitor status, and PANDA index date only. No newly added source was retained; freshness labels applied to retained sources: none. Subscriber count query was unavailable because local Supabase URL/service-role credentials were not present. No external email, Gmail, SMTP, Postmark, subscriber-delivery endpoint, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard/blog/community pages, CISA/NICCS, UK NCSC, Canadian Centre for Cyber Security, CERT-In, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, ransomware-profile, marketing, and IOC Radar/navigation pages, BleepingComputer FortiBleed and FortigateSniffer reporting/tag pages, Hudson Rock/InfoStealers and domain lookup snippets, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, Trend Micro, Bitsight, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, BGD e-GOV CIRT, CERT-PH/DICT social advisory snippets, Fortinet August blog/news items, search-index-only pages, social/video posts, and related public reporting
v4.3
15-Aug-2026 8:08 AM ET
Version: v4.3 Date: 15-Aug-2026 8:08 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 14-August 15 items were Fortinet company/product news unrelated to FortiBleed, Fortinet support/community or packet-sniffer content that did not change the campaign brief, older June/July FortiBleed reporting recrawled today, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel/Picus context already represented, FortiBleed-as-comparator material, vendor/product pages, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 15 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard and community pages, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, Fortinet packet-sniffer documentation, search-index-only pages, social/video posts, and related public reporting
v4.3
14-Aug-2026 8:03 AM ET
Version: v4.3 Date: 14-Aug-2026 8:03 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 13-August 14 items were Fortinet stock/company news unrelated to FortiBleed, Fortinet packet-sniffer documentation unrelated to the FortigateSniffer campaign tool, older June/July FortiBleed reporting recrawled today, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context already represented, FortiBleed-as-comparator material, vendor/product pages, social amplification, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 14 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Dataprise, Field Effect, Dark Reading, CSA Singapore, search-index-only pages, social/video posts, and related public reporting
v4.2
12-Aug-2026 8:02 AM ET
Version: v4.2 Date: 12-Aug-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 11-August 12 items were duplicate summaries, older June/July reporting recrawled today, FortiBleed-as-comparator material, unrelated Fortinet CVE/ransomware reporting, Fortinet product/security pages unrelated to this credential-exposure brief, social amplification, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. Censys' June 19 advisory was newly noticed but not retained because it repeats already represented Fortinet/Hudson Rock/credential-exposure and hardening guidance. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 12 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, Censys, The Register, search-index-only pages, social/video posts, and related public reporting
v4.2
11-Aug-2026 8:03 AM ET
Version: v4.2 Date: 11-Aug-2026 8:03 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 10-August 11 items were duplicate summaries, blocked/unverifiable browser-check pages, older June/July reporting recrawled today, FortiBleed-as-comparator material, Fortinet product/security pages unrelated to this credential-exposure brief, social amplification, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 11 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, IndustrialCyber, Portnox, search-index-only pages, social/video posts, and related public reporting
v4.2
10-Aug-2026 8:04 AM ET
Version: v4.2 Date: 10-Aug-2026 8:04 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 9-August 10 items were duplicate summaries, older SOCRadar FAQ/checker content already represented by current no-new-CVE, credential-reuse, PBKDF2, active-operation, and exposure-check language, FortiBleed-as-comparator material, vendor/product pages unrelated to the FortiBleed brief, social amplification, search-index recrawls, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 10 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, FAQ, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, social/video posts, search-index-only pages, and related public reporting
v4.2
09-Aug-2026 8:05 AM ET
Version: v4.2 Date: 09-Aug-2026 8:05 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 8-August 9 items were duplicate summaries, domain-specific lookup-result snippets not suitable for publication, FortiBleed-as-comparator material, vendor/product pages unrelated to the FortiBleed brief, social amplification, search-index recrawls, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 9 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, social/video posts, search-index-only pages, and related public reporting
v4.2
08-Aug-2026 8:04 AM ET
Version: v4.2 Date: 08-Aug-2026 8:04 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 7-August 8 items were duplicate summaries, weekly roundups, FortiBleed-as-comparator material, vendor/product pages unrelated to the FortiBleed brief, social amplification, search-index recrawls, SEO rewrites, or already represented SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42/Kevin Beaumont/CybelAngel context. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 8 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, whitepaper, IOC/free-tool, webinar, and marketing pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, DataBreachToday/BankInfoSecurity, Cybersecurity Dive, CybelAngel, GBHackers, Rescana, Orca Security, CybersecurityNews, SecurityOnline, CSO Online, IndustrialCyber, ITPro, Portnox, ITBriefcase, Infosec.ge, social/video posts, search-index-only pages, and related public reporting
v4.1
05-Aug-2026 8:01 AM ET
Version: v4.1 Date: 05-Aug-2026 8:01 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 4-August 5 items were Fortinet corporate/product/security pages unrelated to FortiBleed findings, crawled-today duplicate June/July FortiBleed reporting, SOCRadar free-tool and campaign pages already represented in citations 27 and 35, the already represented SOCRadar investigation page showing a July 31 page date without a new retained finding, duplicate Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation, campaign, and whitepaper pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, search-index-only pages, and related public reporting
v4.1
04-Aug-2026 8:01 AM ET
Version: v4.1 Date: 04-Aug-2026 8:01 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 3-August 4 items were crawled-today older reporting, SOCRadar free-tool/IOC pages unrelated to FortiBleed findings, the already represented SOCRadar investigation page showing a July 31 page date without a new retained finding, duplicate Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 4 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed and FortigateSniffer tag/results, Hudson Rock/InfoStealers, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, search-index-only pages, and related public reporting
v4.1
03-Aug-2026 8:01 AM ET
Version: v4.1 Date: 03-Aug-2026 8:01 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 2-August 3 items were crawled-today older reporting, SOCRadar free-tool/IOC pages unrelated to FortiBleed findings, FortiGuard ransomware profile content unrelated to FortiBleed, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 3 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, search-index-only pages, and related public reporting
v4.1
02-Aug-2026 8:02 AM ET
Version: v4.1 Date: 02-Aug-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed August 1-August 2 items were crawled-today older reporting, source tag pages, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, unrelated Fortinet company or vulnerability content, FortiBleed-as-comparator material, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 2 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, retry workflow, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, and related public reporting
v4.1
01-Aug-2026 8:02 AM ET
Version: v4.1 Date: 01-Aug-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed July 31-August 1 items were crawled-today older reporting, source tag pages, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, unrelated Fortinet company or vulnerability content, FortiBleed-as-comparator material, SEO rewrites, social/video posts, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable August 1 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont/DoublePulsar, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, IndustrialCyber, ITPro, social/video posts, and related public reporting
v4.1
31-Jul-2026 8:02 AM ET
Version: v4.1 Date: 31-Jul-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed July 30-July 31 items were crawled-today older reporting, broader VPN/ransomware or edge-infrastructure context, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, unrelated Fortinet company or vulnerability content, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 31 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, CSO Online, BankInfoSecurity, Cyber Press, SecurityOnline, social/video posts, and related public reporting
v4.1
30-Jul-2026 8:03 AM ET
Version: v4.1 Date: 30-Jul-2026 8:03 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed July 29-July 30 items were crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/NCSC/Hudson Rock/BleepingComputer/Recorded Future/Unit 42 context already represented, unrelated Fortinet company or vulnerability content, social/video posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 30 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer FortiBleed tag/results, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, Picus, Shadowserver, Cloud Security Alliance, Bitdefender, The Hacker News, ITPro, IndustrialCyber, social/video posts, and related public reporting
v4.1
29-Jul-2026 8:02 AM ET
Version: v4.1 Date: 29-Jul-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed July 28-July 29 items were business-oriented recaps, crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/NCSC/WaterISAC/Recorded Future/Unit 42/Hudson Rock/BleepingComputer context already represented, unrelated Fortinet industry-trend content, social posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 29 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, PatriotGIS, Cloud Security Alliance, Bitdefender, The Hacker News, and related public reporting
v4.1
28-Jul-2026 8:02 AM ET
Version: v4.1 Date: 28-Jul-2026 8:02 AM ET Release Type: AI monitoring check (no content delta) What Changed: AI Monitoring Agent checked public FortiBleed/Fortinet/FortiGate credential-exposure sources; no source-backed FortiBleed content update was identified, and the product version was not incremented. Newly observed July 27-July 28 items were policy and legacy-VPN context referencing FortiBleed, crawled-today older reporting, duplicate SOCRadar/Fortinet/CISA/Unit 42/Hudson Rock/BleepingComputer context already represented, unrelated Fortinet vulnerability news, social posts, SEO rewrites, or unsupported claims. SOCRadar FortiBleed Check retained already represented headline metrics and did not show a verifiable July 28 checker update timestamp in retrieved page text. Updated audit trail, metadata modified timestamp, and PANDA index date only. No external email, subscriber alert, Gmail, SMTP, Postmark, or notification workflow was used under the automation no-email policy. Source / Basis: Source check: Fortinet PSIRT/FortiGuard, CISA/NICCS, UK NCSC, WaterISAC, SOCRadar FortiBleed Check, SOCRadar investigation and whitepaper pages, BleepingComputer, Hudson Rock, Recorded Future, Unit 42, Security Affairs, Diachenko, Kevin Beaumont, Arctic Wolf, Sophos, SpyCloud, Huntress, ITPro, CSO Online, CyberScoop, Wyden Senate letter, CUInfoSecurity, CybersecurityNews, The Hacker News, Dark Reading, BankInfoSecurity, Cloud Security Alliance, and related public reporting
Citations
1
Tier 2
#: 1 Tier: Tier 2 Publisher: Threat-Modeling.com Published: June 18, 2026 Why Used: Limited public-account context on disclosure timing and general Fortinet VPN credential-exposure framing; high-specificity mechanism claims require corroboration. Source: FortiBleed: Fortinet VPN Credentials Exposed for 73,000 Devices https://threat-modeling.com/fortibleed-fortinet-vpn-credential-leak-june-2026/
https://threat-modeling.com/fortibleed-fortinet-vpn-credential-leak-june-2026/2
Tier 2
#: 2 Tier: Tier 2 Publisher: Kudelski Security Published: Not available Why Used: Retained as a relevant collection lead. The retained excerpt was mostly cookie or consent content and is not used for substantive findings. Source: Fortinet FortiBleed Global Compromise & Active Exploitation of Fortinet Vulnerabilities https://kudelskisecurity.com/research/fortinet-fortibleed-global-compromise-active-exploitation-of-fortinet-vulnerabilities
https://kudelskisecurity.com/research/fortinet-fortibleed-global-compromise-active-exploitation-of-fortinet-vulnerabilities3
Tier 2
#: 3 Tier: Tier 2 Publisher: ITKnowledgeBases Published: June 17, 2026 Why Used: Used for cautious characterization, 73,932 URL and 21,632 domain figures, exposed data categories, non-CVE caveat, and immediate defender actions. Source: FortiBleed: 75,000 Fortinet Firewalls Compromised - CVEs, Attack Chain, and How to Detect It https://itknowledgebases.com/fortibleed-fortinet-firewalls-compromised/
https://itknowledgebases.com/fortibleed-fortinet-firewalls-compromised/4
Tier 3
#: 4 Tier: Tier 3 Publisher: BleepingComputer Published: June 18, 2026 Why Used: Core corroboration that FortiBleed exposed what appear to be Fortinet/FortiGate VPN credentials for 73,932 firewall URLs, including usernames, emails, and plaintext passwords. Source: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/
https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/5
Tier 3
#: 5 Tier: Tier 3 Publisher: CyberUnit Published: June 17, 2026 Why Used: Used for 73,932 Fortinet firewall or SSL VPN URLs, 194-country scope, exposed usernames, emails, plaintext passwords in many cases, and no-new-CVE framing. Source: FortiBleed: What the Fortinet Firewall Credential Campaign Means for SMBs in Canada and the US https://cyberunit.com/insights/fortibleed-fortinet-firewall-vpn-credential-attack/
https://cyberunit.com/insights/fortibleed-fortinet-firewall-vpn-credential-attack/6
Tier 3
#: 6 Tier: Tier 3 Publisher: Hackread Published: June 17, 2026 Why Used: Used for 73,932 unique firewall URLs, 194 countries, 21,632 affected domains, Bob Diachenko and Hudson Rock attribution, and the reported free Hudson Rock lookup portal. Source: FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries https://hackread.com/fortibleed-attack-fortinet-firewalls-credentials/
https://hackread.com/fortibleed-attack-fortinet-firewalls-credentials/7
Tier 3
#: 7 Tier: Tier 3 Publisher: DataBreaches.net Published: June 18, 2026 Why Used: Retained as a collection lead only. The available excerpt was a security-verification page and does not support substantive claims. Source: Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries https://databreaches.net/2026/06/18/active-fortibleed-campaign-impacting-fortinet-devices-across-194-countries/
https://databreaches.net/2026/06/18/active-fortibleed-campaign-impacting-fortinet-devices-across-194-countries/8
Tier 3
#: 8 Tier: Tier 3 Publisher: CSO Online Published: June 18, 2026 Why Used: Used for mainstream corroboration, persistent-access warnings, Diachenko's potentially working password-list description, and SOCRadar's reported operational-server finding. Source: FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide https://www.csoonline.com/article/4186790/fortibleed-campaign-exposes-75000-fortinet-firewalls-worldwide.html
https://www.csoonline.com/article/4186790/fortibleed-campaign-exposes-75000-fortinet-firewalls-worldwide.html9
Tier 1
#: 9 Tier: Tier 1 Publisher: Hudson Rock Published: June 17, 2026 Why Used: Primary Hudson Rock FortiBleed writeup and ethical-disclosure context for the affected-domain lookup workflow and dataset framing. Source: Global Enterprises Exposed - Claim Your Ethical Disclosure https://www.hudsonrock.com/blog/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure
https://www.hudsonrock.com/blog/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure10
Tier 1
#: 10 Tier: Tier 1 Publisher: Hudson Rock Published: Not available Why Used: Primary lookup portal for organizations to check whether their domain appears in Hudson Rock's FortiBleed dataset. Source: FortiBleed - 73932+ Compromised Fortinet Firewalls https://www.hudsonrock.com/fortinet
https://www.hudsonrock.com/fortinet11
Tier 1
#: 11 Tier: Tier 1 Publisher: Volodymyr Bob Diachenko / LinkedIn Published: June 2026 Why Used: Researcher-origin social signal for discovery timing, screenshot context, affected-domain scale, and the claim that passwords were potentially working. Source: Fortinet FortiGate Bruteforce Campaign Exposed https://www.linkedin.com/posts/vdyachenko_massive-fortinetfortigate-bruteforceactive-activity-7471222472193830913-YBDi
https://www.linkedin.com/posts/vdyachenko_massive-fortinetfortigate-bruteforceactive-activity-7471222472193830913-YBDi12
Tier 1
#: 12 Tier: Tier 1 Publisher: SOCRadar Published: June 16, 2026; updated June 29, 2026 9:00 AM EST Why Used: Primary security-company reporting on FortiBleed scale, operational infrastructure, credential validation, top exposed username patterns, and scoping implications. 30-Jun-2026 · Revised Freshly reported (<24h): SOCRadar's June 29 update attributes FortiBleed to Lynx / INC and says a full technical report is forthcoming; retrieved June 30, 2026 8:03 AM ET. Source: FortiBleed 2026: 86,644 Fortinet Firewalls Compromised https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/
https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/13
Tier 0
#: 13 Tier: Tier 0 Publisher: Fortinet PSIRT Published: June 19, 2026 Why Used: Official Fortinet response stating the activity is not a new Fortinet vulnerability, is not tied to a recent incident/advisory, and appears to involve credential reuse and brute-force activity. Source: Analysis of Reported Credential Compromise of FortiGate Devices https://www.fortinet.com/lat/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices
https://www.fortinet.com/lat/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices14
Tier 0
#: 14 Tier: Tier 0 Publisher: CISA Published: June 18, 2026 Why Used: Authoritative government hardening alert for terminating sessions, resetting VPN/admin passwords, enabling phishing-resistant MFA, and reviewing logs. Source: CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure15
Tier 1
#: 15 Tier: Tier 1 Publisher: Kevin Beaumont / DoublePulsar Published: June 2026 Why Used: Independent practitioner analysis on cracked admin passwords, configuration-export uncertainty, and Fortinet credential-storage implications. Source: FortiBleed - 75k Fortinet firewalls have admin passwords cracked https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8
https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f816
Tier 3
#: 16 Tier: Tier 3 Publisher: Security Affairs Published: June 18, 2026 Why Used: Corroborating security-news report linking Diachenko, Beaumont, Hudson Rock, and FortiBleed; useful for named-company examples, configuration-export discussion, Hashtopolis/45-GPU claims, and concrete scoping guidance. Source: FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls https://securityaffairs.com/193817/hacking/fortibleed-exposes-admin-passwords-for-75000-fortinet-firewalls.html
https://securityaffairs.com/193817/hacking/fortibleed-exposes-admin-passwords-for-75000-fortinet-firewalls.html17
Expansion Research
#: 17 Tier: Expansion Research Publisher: Huntress Published: June 18, 2026 Why Used: Enhanced-research source for MSP/partner scoping, cleartext credential and Kerberos-hash context, partner-corpus cross-reference value, and broad Active Directory credential-rotation rationale. Source: 2026-June Fortibleed Credential Exposure https://support.huntress.io/hc/en-us/articles/52698652545171-2026-June-Fortibleed-Credential-Exposure
https://support.huntress.io/hc/en-us/articles/52698652545171-2026-June-Fortibleed-Credential-Exposure18
Expansion Research
#: 18 Tier: Expansion Research Publisher: WaterISAC Published: June 18, 2026 Why Used: Enhanced-research source for utility-sector scoping, outsourced-technology-provider implications, session termination, credential reset, MFA, trusted-management access, PBKDF2, and unauthorized-account review. Source: (TLP:CLEAR) Widespread FortiBleed Credential Exposure Campaign Affects Fortinet Firewalls and VPN Gateways https://www.waterisac.org/tlpclear-widespread-fortibleed-credential-exposure-campaign-affects-fortinet-firewalls-and-vpn-gateways
https://www.waterisac.org/tlpclear-widespread-fortibleed-credential-exposure-campaign-affects-fortinet-firewalls-and-vpn-gateways19
Expansion Research
#: 19 Tier: Expansion Research Publisher: Field Effect Published: June 18, 2026 Why Used: Enhanced-research source for identity-as-attack-surface framing, common Fortinet access ports, configuration-file collection, credential reuse, older hash storage, and partial-visibility caveats. Source: FortiBleed exposes Fortinet credentials at global scale https://fieldeffect.com/blog/fortibleed-exposes-fortinet-credentials
https://fieldeffect.com/blog/fortibleed-exposes-fortinet-credentials20
Expansion Research
#: 20 Tier: Expansion Research Publisher: Arctic Wolf Published: June 17, 2026 Why Used: Enhanced-research source for validated-working-credential claims, 30,791-device SOCRadar figure, PBKDF2 migration nuance, old-password caveat, and Fortinet management-interface hardening. Source: Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries https://arcticwolf.com/resources/blog/active-fortibleed-campaign-impacting-fortinet-devices-across-194-countries/
https://arcticwolf.com/resources/blog/active-fortibleed-campaign-impacting-fortinet-devices-across-194-countries/21
Expansion Research
#: 21 Tier: Expansion Research Publisher: HKCERT Published: June 18, 2026 Why Used: Enhanced-research source for regional CERT-style warning that Hong Kong organizations may be affected and that Fortinet credential exposure should trigger local validation. Source: Security Alert - FortiBleed Credential Leak Incident https://www.hkcert.org/security-bulletin/security-alert-fortibleed-credential-leak-incident-over-70-000-fortinet-devices-suspected-to-be-affected-by-data-and-credential-exposure-hong-kong-organisations-may-be-affected_20260618
https://www.hkcert.org/security-bulletin/security-alert-fortibleed-credential-leak-incident-over-70-000-fortinet-devices-suspected-to-be-affected-by-data-and-credential-exposure-hong-kong-organisations-may-be-affected_2026061822
Expansion Research
#: 22 Tier: Expansion Research Publisher: SecurityWeek Published: June 19, 2026 Why Used: Enhanced-research source for newer higher-scale reporting and the need to preserve baseline-vs-expanded count distinctions. Source: FortiBleed: 86,000 Fortinet Device Credentials Compromised https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/
https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/23
Expansion Research
#: 23 Tier: Expansion Research Publisher: Bitsight Published: June 18, 2026 Why Used: Enhanced-research source for third-party cyber-risk and exposure-management framing around Fortinet VPN credential and configuration-data exposure. Source: Major Security Event: Fortinet VPN Credentials and Configuration Data Exposed for 73,000 Devices https://www.bitsight.com/blog/security-alert-fortibleed-fortinet-vpn-credentials-firewall-exposed
https://www.bitsight.com/blog/security-alert-fortibleed-fortinet-vpn-credentials-firewall-exposed24
Expansion Research
#: 24 Tier: Expansion Research Publisher: IBM X-Force Published: June 19, 2026 Why Used: Enhanced-research source for broader secure-remote-access gateway risk context across Fortinet FortiGate SSL VPN and other internet-facing VPN infrastructure. Source: Palo Alto and Fortinet Secure Remote Access Gateway / VPN Compromise Advisory https://www.ibm.com/think/x-force/palo-alto-fortinet-secure-remote-access-gateway-vpn-compromise-advisory
https://www.ibm.com/think/x-force/palo-alto-fortinet-secure-remote-access-gateway-vpn-compromise-advisory25
Expansion Research
#: 25 Tier: Expansion Research Publisher: SOCRadar STRU Published: June 22, 2026 Why Used: 22-Jun-2026 · AI Agent delta SOCRadar's in-depth update describes FortigateSniffer, 430,000+ targeted FortiGate firewalls, 260+ operation servers, 659+ harvest cycles, 110M+ harvested credential records or credential artifacts, credential harvesting across 24 protocols, and IAB-style operator assessment. Source: Dismantling FortiBleed: Inside a Russian Fortinet Compromise Operation https://socradar.io/resources/whitepapers/dismantling-fortibleed-inside-a-russian-fortinet-compromise-operation/
https://socradar.io/resources/whitepapers/dismantling-fortibleed-inside-a-russian-fortinet-compromise-operation/26
Expansion Research
#: 26 Tier: Expansion Research Publisher: BleepingComputer Published: June 22, 2026 Why Used: 22-Jun-2026 · AI Agent delta Corroborates SOCRadar's update and explains FortigateSniffer, FortiOS diagnose sniffer packet abuse, SNIFTRAN/PCAP parsing, credential extraction, and Hashcat/GPU cracking context. Source: FortiBleed campaign used custom FortiGate sniffer to steal credentials https://www.bleepingcomputer.com/news/security/fortibleed-campaign-used-custom-fortigate-sniffer-to-steal-credentials/
https://www.bleepingcomputer.com/news/security/fortibleed-campaign-used-custom-fortigate-sniffer-to-steal-credentials/27
Expansion Research
#: 27 Tier: Expansion Research Publisher: SOCRadar Published: Last updated July 20, 2026 Why Used: 22-Jun-2026 · AI Agent delta SOCRadar exposure-check page with updated live-campaign framing, 437K+ targeted devices, 90K+ IPs, 750K+ credentials, 105M+ records, and no-signup domain/IP/CIDR lookup workflow. 24-Jun-2026 · Revised The page showed a June 24 update timestamp and said new compromised devices continued to be added. 26-Jun-2026 · Revised The checker showed a June 26 update timestamp while retaining the same headline metrics. 27-Jun-2026 · Revised Freshly reported (<24h): the checker showed a June 27 update timestamp while retaining the same headline metrics. 29-Jun-2026 · Revised Freshly reported (<24h): the checker now shows a June 29 update timestamp, retains the same headline metrics, and adds a 59.3M-host active scanning figure. 1-Jul-2026 · Revised Freshly reported (<24h): the checker showed a July 1 update timestamp, said new compromised devices were being added, and retained the 437K+ targeted-device, 90K+ IP, 750K+ credential, and 105M+ record headline metrics. 3-Jul-2026 · Revised Newly retained; exact update time unavailable: the checker showed a July 2 update date, said new compromised devices were being added, and retained the same headline metrics. 5-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: the checker showed a July 5 update date, said new compromised devices were being added, and retained the same headline metrics. 7-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: the checker showed a July 7 update date, said new compromised devices were being added, and retained the same headline metrics. 8-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: the checker showed a July 8 update date, said new compromised devices were being added, and retained the same headline metrics. 9-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: indexed public SOCRadar checker content showed a July 9 update date, said new compromised devices were being added, and retained the same headline metrics. 11-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check showed a July 11 update date, said new compromised devices were being added, and retained the same headline metrics. 12-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check showed a July 12 update date, said new compromised devices were being added, and retained the same headline metrics. 13-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check showed a July 13 update date, said new compromised devices were being added, and retained the same headline metrics. 14-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check showed a July 14 update date, said new compromised devices were being added, and retained the same headline metrics. 15-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check showed a July 15 update date, said new compromised devices were being added, and retained the same headline metrics. 16-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check showed a July 16 update date, said new compromised devices were being added, and retained the same headline metrics. 17-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check showed a July 17 update date, said new compromised devices were being added, and retained the same headline metrics. Retrieved July 17, 2026 8:03 AM ET. 18-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check showed a July 18 update date, said new compromised devices were being added, and retained the same headline metrics. Retrieved July 18, 2026 8:03 AM ET. 19-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check showed a July 19 update date, said new compromised devices were being added, and retained the same headline metrics. Retrieved July 19, 2026 8:02 AM ET. 20-Jul-2026 · Revised Freshly reported (<24h); exact update time unavailable: SOCRadar FortiBleed Check now shows a July 20 update date, says new compromised devices are being added, and retains the same headline metrics. Retrieved July 20, 2026 8:03 AM ET. Source: FortiBleed Check https://socradar.io/free-tools/fortibleed
https://socradar.io/free-tools/fortibleed28
Expansion Research
#: 28 Tier: Expansion Research Publisher: Security Affairs Published: June 22, 2026 Why Used: 22-Jun-2026 · AI Agent delta Secondary but useful synthesis of SOCRadar's detailed update, including 430,000+ targeted FortiGate devices, FortigateSniffer, 24 protocols, 659+ harvesting pipelines, SMB victimology, and defensive recommendations. Source: FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation.html
https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation.html29
Expansion Research
#: 29 Tier: Expansion Research Publisher: SpyCloud Labs Published: June 19, 2026 Why Used: 23-Jun-2026 · AI Agent delta Adds source-backed infrastructure analysis describing three campaign server roles, broader Synology/Sophos/MSSQL scanning, AI-assisted tooling, IAB-style monetization, SantaAd forum signal, and redacted sensitive exfiltration evidence. Source: More Than a Leak: What SpyCloud Found Inside the FortiBleed Threat Actor Infrastructure https://spycloud.com/blog/what-spycloud-found-inside-the-fortibleed-threat-actor-infrastructure/
https://spycloud.com/blog/what-spycloud-found-inside-the-fortibleed-threat-actor-infrastructure/30
Expansion Research
#: 30 Tier: Expansion Research Publisher: Sophos Published: First published June 20, 2026 Why Used: 23-Jun-2026 · AI Agent delta Official Sophos advisory stating the same threat actors also targeted internet-exposed Sophos Firewall appliances through user-level credential brute-forcing/stuffing, while Sophos had not observed Sophos Firewall compromise or vulnerability exploitation in reviewed telemetry. Source: Advisory: Fortinet FortiBleed Credential Exposure and Sophos VPN Bruteforcing Campaign https://www.sophos.com/en-us/security-advisories/fortinet-fortibleed-credential-exposure-and-sophos-vpn-bruteforcing-campaign
https://www.sophos.com/en-us/security-advisories/fortinet-fortibleed-credential-exposure-and-sophos-vpn-bruteforcing-campaign31
Expansion Research
#: 31 Tier: Expansion Research Publisher: Arctic Wolf Published: June 23, 2026 Why Used: 24-Jun-2026 · AI Agent delta Reverse-engineering report on a recovered CyberStrike Harvester binary and FortiBleed toolchain, including credential stuffing, password spraying, configuration harvesting, offline cracking, post-authentication capture processing, AD/SMB tooling, and low-confidence Russian-speaking operator indicators. Source: Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory https://arcticwolf.com/resources/blog/inside-fortibleed-reverse-engineering-the-cyberstrike-harvester-behind-a-global-fortigate-credential-factory/
https://arcticwolf.com/resources/blog/inside-fortibleed-reverse-engineering-the-cyberstrike-harvester-behind-a-global-fortigate-credential-factory/32
Expansion Research
#: 32 Tier: Expansion Research Publisher: Unit 42 Published: June 26, 2026 Why Used: 27-Jun-2026 · Revised Freshness corrected: Unit 42 shows a June 26 publication date. Corroborates a multi-stage credential attack pattern across Fortinet, MSSQL, and reported Sophos targets, with password spraying, possible configuration extraction, offline cracking, unvalidated forum-sale claims, and suspicious login attempts observed in Unit 42 customer telemetry. Unit 42 explicitly says this activity was not targeting Palo Alto Networks devices. Source: Threat Brief: Mitigating Large-Scale Credential Attacks https://unit42.paloaltonetworks.com/large-scale-credential-attacks/
https://unit42.paloaltonetworks.com/large-scale-credential-attacks/33
Expansion Research
#: 33 Tier: Expansion Research Publisher: SANS NewsBites Published: June 23, 2026 Why Used: 24-Jun-2026 · AI Agent delta Practitioner/editorial corroboration that perimeter-security-device incident playbooks should consider traffic visible to a compromised firewall, management-interface exposure, MFA, backdoor checks, and possible device replacement in severe cases. Source: NewsBites Volume XXVIII - Issue 46 https://www.sans.org/newsletters/newsbites/xxviii-46
https://www.sans.org/newsletters/newsbites/xxviii-4634
Expansion Research
#: 34 Tier: Expansion Research Publisher: Recorded Future Insikt Group Published: June 19, 2026 Why Used: 26-Jun-2026 · AI Agent delta Newly retained; published >24h before this run. Adds source-backed seller-credibility deconfliction, FortiBleed workflow context, and caution around copycat/re-extortion claims. 5-Jul-2026 · Checked User-supplied revisit confirmed this source remains relevant for behavior-level workflow and infrastructure scoping; raw infrastructure, artifacts, victim references, and acquisition details are intentionally not republished. Retrieved June 26, 2026 8:03 AM ET; revisited July 5, 2026 5:43 PM ET. Source: FortiBleed Campaign Exposes Credentials for 73,932 FortiGate Systems https://www.recordedfuture.com/blog/critical-fortibleed-campaign
https://www.recordedfuture.com/blog/critical-fortibleed-campaign35
Expansion Research
#: 35 Tier: Expansion Research Publisher: SOCRadar Published: June 27, 2026 Why Used: 27-Jun-2026 · AI Agent delta Freshly reported (<24h): SOCRadar's public campaign page adds current campaign-card metrics: 80,553 unique devices, 23,406 organizational domains, 659 documented harvest cycles, 430,000+ FortiGate targets, and 110M+ credentials. Retrieved June 27, 2026 8:03 AM ET; raw IPs, hashes, victim details, and operational artifacts are intentionally not republished. Source: FortiBleed - Campaigns https://socradar.io/free-tools/campaigns/1722
https://socradar.io/free-tools/campaigns/172236
Expansion Research
#: 36 Tier: Expansion Research Publisher: SOCRadar STRU Published: July 2, 2026 Why Used: 2-Jul-2026 · AI Agent delta Freshly reported (<24h): SOCRadar links FortiBleed infrastructure to INC Ransom and Lynx ransomware operations, reports 200+ additional operational servers, roughly 11,250 FortiGate portals scanned across 150+ countries, admin-level access confirmed on 409 targets, full domain compromise on 354, at least 12 ransomware deployments, and an organized roughly 20-person operation. Retrieved July 2, 2026 8:03 AM ET; operator aliases, full indicators, raw infrastructure, victim details, and technical artifacts remain withheld. Source: SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Operations https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/
https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/37
Expansion Research
#: 37 Tier: Expansion Research Publisher: The Times Published: July 5, 2026 Why Used: 6-Jul-2026 · AI Agent delta Freshly reported (<24h): UK reporting says FortiBleed-linked stolen-login activity affected UK Foreign Office and council account examples and cites roughly 80,000 Fortinet security-firewall accounts in the reporting cluster. Retained as public-sector exposure context only; no raw credentials, account lists, or victim dataset rows are republished. Retrieved July 6, 2026 8:55 AM ET. Source: Hackers breach Foreign Office systems with stolen logins https://www.thetimes.com/uk/technology-uk/article/hackers-breach-foreign-office-systems-logins-nhd0rgr3v
https://www.thetimes.com/uk/technology-uk/article/hackers-breach-foreign-office-systems-logins-nhd0rgr3v38
Expansion Research
#: 38 Tier: Expansion Research Publisher: The Sun Published: Published July 5, 2026 14:24; updated July 5, 2026 20:19 Why Used: 6-Jul-2026 · AI Agent delta Freshly reported (<24h): accessible UK follow-on reporting says a list seen by The Telegraph included Foreign Office overseas and local-government staff examples, states NCSC issued an urgent Fortinet brute-force alert, and attributes the activity to previously stolen credentials. Retained to qualify public-sector examples and response urgency, not to publish sensitive list details. Retrieved July 6, 2026 8:55 AM ET. Source: Russian hackers stole UK government official's logins to infiltrate email accounts in major national security breach https://www.the-sun.com/news/16638944/russian-hackers-uk-government-data-email-breach/
https://www.the-sun.com/news/16638944/russian-hackers-uk-government-data-email-breach/39
Expansion Research
#: 39 Tier: Expansion Research Publisher: UK National Cyber Security Centre Published: June 18, 2026 Why Used: 7-Jul-2026 · AI Agent delta Newly retained; published >24h before this run: official UK NCSC alert corroborates Fortinet firewall and VPN-gateway targeting, recommends FortiBleed checker validation, IoC review, isolation where compromise evidence exists, factory reset where persistence is possible, shared-credential scoping, management-interface hardening, MFA, and PBKDF2 enforcement. Retrieved July 7, 2026 8:02 AM ET. Source: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways
https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways40
Expansion Research
#: 40 Tier: Expansion Research Publisher: SOCRadar Published: Exact landing-page timestamp unavailable; public references observed July 6, 2026 Why Used: 22-Jul-2026 · AI Agent delta Newly retained; published >24h before this run. SOCRadar's public Volume II landing page removes the earlier pending-whitepaper caveat and adds high-level support for FortiBleed-to-Lynx/INC linkage, operator and hierarchy analysis, victim-workflow mapping, AI-assisted offensive operations, technical profiling, targeting analysis, ATT&CK mapping, and IoC availability. Retrieved July 22, 2026 8:04 AM ET; operator-detail, IoC, victim, infrastructure, and artifact handling remains source-caveated and not republished as raw material. Source: FortiBleed Unmasked: A Joint Operation by Lynx and INC Ransomware Groups https://socradar.io/resources/whitepapers/fortibleed-unmasked-inside-the-lynx-and-inc-ransomware-operation/
https://socradar.io/resources/whitepapers/fortibleed-unmasked-inside-the-lynx-and-inc-ransomware-operation/41
Expansion Research
#: 41 Tier: Expansion Research Publisher: CHT Security Published: July 25, 2026 03:50 Taiwan time Why Used: 27-Jul-2026 · AI Agent delta Newly retained; published >24h before this run. CHT Security says its name appeared in recent FortiBleed intelligence reporting because its FortiSupport Partner account had been used during prior customer product-registration and support workflows, not because CHT Security's internal environment was compromised. Retrieved July 27, 2026 8:02 AM ET; retained as first-party deconfliction and notification-workflow context, not as proof of FortiBleed impact at CHT Security or its customers. Source: CHT Security clarification on recent FortiBleed intelligence reporting https://www.chtsecurity.com/news/0a0d95f1-164c-46ca-9b27-03f8a4865e2c
https://www.chtsecurity.com/news/0a0d95f1-164c-46ca-9b27-03f8a4865e2c42
Expansion Research
#: 42 Tier: Expansion Research Publisher: CybelAngel REACT Published: June 25, 2026 Why Used: 7-Aug-2026 · AI Agent delta Newly retained; published >24h before this run. CybelAngel's public flash-report summary adds planted Fortinet-service-like administrator account names and reinforces the persistence-review path after a FortiBleed exposure match. Retrieved August 7, 2026 8:02 AM ET; raw infrastructure, victim rows, credentials, and sensitive dataset material remain unpublished. Source: 8 Days After FortiBleed: What We Know Now [Flash Report] https://cybelangel.com/blog/8-days-after-fortibleed-what-we-know/
https://cybelangel.com/blog/8-days-after-fortibleed-what-we-know/43
Expansion Research
#: 43 Tier: Expansion Research Publisher: Roche Diagnostics Published: Published June 30, 2026; last updated June 30, 2026 Why Used: 13-Aug-2026 · AI Agent delta Newly retained; published >24h before this run. Roche's first-party advisory says its investigation found two Roche-associated FortiGate devices in the FortiBleed dataset but no evidence of impact to Roche customer Laboratory Networks. Retrieved August 13, 2026 8:12 AM ET; retained as first-party deconfliction and customer-impact boundary context, not as raw exposure evidence. Source: FortiBleed - Roche's Response to Fortinet Credential Exposure https://diagnostics.roche.com/global/en/legal/product-security-advisory.html
https://diagnostics.roche.com/global/en/legal/product-security-advisory.html44
Expansion Research
#: 44 Tier: Expansion Research Publisher: BGD e-GOV CIRT Published: Published July 7, 2026 15:30:00 Why Used: 16-Aug-2026 · AI Agent delta Newly retained; published >24h before this run. Bangladesh national CIRT advisory identifies 153 unique Bangladesh IP addresses associated with the FortiBleed tag and requiring investigation. Retrieved August 16, 2026 8:08 AM ET; retained as regional scoping evidence, not proof that every tagged address was compromised. Source: FortiBleed Campaign Exposes FortiGate Devices in Bangladesh with Credential Compromise https://www.cirt.gov.bd/advisories/fortibleed-campaign-bd
https://www.cirt.gov.bd/advisories/fortibleed-campaign-bd45
Expansion Research
#: 45 Tier: Expansion Research Publisher: Canadian Centre for Cyber Security Published: Published June 18, 2026; date modified June 18, 2026 Why Used: 26-Aug-2026 · AI Agent delta Newly retained; published >24h before this run. Canada's Cyber Centre says it became aware on June 17, 2026 of open-source FortiBleed reporting involving exposed credentials affecting Fortinet firewalls and VPN gateways; it recommends Fortinet account inventory, removal of suspicious or unneeded accounts including forticloud-sync and forticloud-tech, management-interface restriction, session termination, password reset, MFA enforcement, firmware review, internet-gateway defense, privilege-management, and reporting matching activity through Canadian Cyber Centre channels. Retrieved August 26, 2026 8:02 AM ET; retained as official Canadian response guidance, not as a raw victim, credential, or compromise-count source. Source: AL26-014 - FortiBleed leak of thousands of compromised credentials impacting Fortinet devices https://www.cyber.gc.ca/en/alerts-advisories/al26-014-fortibleed-leak-thousands-compromised-credentials-impacting-fortinet-devices
https://www.cyber.gc.ca/en/alerts-advisories/al26-014-fortibleed-leak-thousands-compromised-credentials-impacting-fortinet-devicesBaseline Retained Sources
Expansion Research Sources

Social Media / Community Signals
LinkedIn
The Diachenko LinkedIn post is retained as the researcher-origin social signal for the FortiGate brute-force/active exploitation disclosure and screenshot context.
Venue / Community Signal: LinkedIn What Retained Reporting Says: The Diachenko LinkedIn post is retained as the researcher-origin social signal for the FortiGate brute-force/active exploitation disclosure and screenshot context. Defender Use: Use the post for discovery timing, exact wording, screenshot context, and source pivots. Caveat: Treat it as researcher social evidence; validate operational impact through owned telemetry and stronger primary or vendor sources.[11]
Security-news reporting
Multiple public security publications reported the dataset, exposed fields, named-company examples, and scale figures.
Venue / Community Signal: Security-news reporting What Retained Reporting Says: Multiple public security publications reported the dataset, exposed fields, named-company examples, and scale figures. Defender Use: Use converging public reporting to justify immediate internal scoping and credential response. Caveat: Public reporting remains secondary for Hudson Rock methodology, Diachenko discovery details, and SOCRadar technical details.[3] [4] [5] [6] [8] [16]
Lookup portal signal
Hudson Rock hosts a FortiBleed lookup portal for organizations to check whether domains appear in the dataset.
Venue / Community Signal: Lookup portal signal What Retained Reporting Says: Hudson Rock hosts a FortiBleed lookup portal for organizations to check whether domains appear in the dataset. Defender Use: Use as a possible scoping channel for affected-domain checks. Caveat: The retained source does not provide portal access requirements, completeness, or validation process.[10]
Other public/community venues
SpyCloud reports access-broker forum signal involving SantaAd and related pricing behavior after public FortiBleed reporting. 26-Jun-2026 · Added Recorded Future/Insikt assesses SantaAd as likely credible for a FortiBleed-related sale claim, while warning that a separate actor reused SantaAd language in a likely low-credibility copycat or re-extortion effort.
Venue / Community Signal: Other public/community venues What Retained Reporting Says: SpyCloud reports access-broker forum signal involving SantaAd and related pricing behavior after public FortiBleed reporting. 26-Jun-2026 · Added Recorded Future/Insikt assesses SantaAd as likely credible for a FortiBleed-related sale claim, while warning that a separate actor reused SantaAd language in a likely low-credibility copycat or re-extortion effort. Defender Use: Treat as access-broker monetization and deconfliction context, not as confirmed attribution or proof of successful resale. Caveat: Do not publish forum artifacts, buyer details, raw marketplace claims, victim-specific access listings, infrastructure, or acquisition instructions.[29] [34]