$ intel.mask2.ca

ADVISORY · 2026-06-18 · SRC ARCTIC-WOLF · CRITICAL
2026-06-18 critical REL 9/10

FortiBleed: Large-scale credential compromise campaign targets FortiGate firewalls globally

governmenthealthcareenergypost-secondaryfinancemsp

A widespread campaign called FortiBleed has compromised FortiGate firewall devices across 194 countries by extracting configuration files and cracking password hashes to obtain administrator credentials. Researchers estimate between 30,000 and 75,000 devices have been affected, with threat actors obtaining verified working credentials for administrative access.

Why it matters in Western Canada: FortiGate firewalls are commonly deployed in Western Canadian organizations across government, healthcare, energy, and post-secondary sectors as primary network security controls. Compromised admin credentials could provide attackers with direct access to critical infrastructure and sensitive data systems.


Summary generated from the original advisory. Read the full source: arctic-wolf

Source
https://arcticwolf.com/resources/blog/active-fortibleed-campaign-impacting-fortinet-devices-across-194-countries/
CVEs
None listed
Tags
fortigate, credentials, firewall, campaign, fortinet
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)