FBI and Secret Service warn the FortiBleed campaign is still active, with SOCRadar reporting 86,000+ compromised FortiGate devices in 194 countries.
Listen/Read: hackread.com/fbi-fortible...

FBI and Secret Service warn the FortiBleed campaign is still active, with SOCRadar reporting 86,000+ compromised FortiGate devices in 194 countries.
Listen/Read: hackread.com/fbi-fortible...
FortiBleed credential-harvesting campaign exploits Fortinet firewalls, compromising 86,644 devices worldwide and locking out admins. #FortiBleed #Fortinet https://securityaffairs.com/200558/cyber-crime/fortibleed-hit-86000-firewalls-by-exploiting-something-nobody-can-patch-away.html
🙄 FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
This campaign isn’t exploiting a new Fortinet flaw: US agencies say attackers are using stolen or weak passwords to reach internet-facing FortiGate…
FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
🔗 Read more: www.helpnetsecurity.com/2026/10/07/f...
FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
🔗 Read more: www.helpnetsecurity.com/2026/10/07/f...
The FortiBleed operation is still targeting Fortinet FortiGate devices, U.S. agencies warn.
Attackers are using leaked or reused passwords;…
The ClingSTUN Linux backdoor hides in public STUN traffic and turns old routers into proxy nodes. See the exploited CVEs and how to detect it.
#ClingSTUN #LinuxMalware #Backdoor #STUN #FortiGuard #Fortinet #RouterSecurity #IoTSecurity
FortiBleed is still active, targeting Fortinet firewalls and VPN gateways. Stolen credentials are used to create admin accounts, reset passwords, lock out users, and enable ransomware access. #FortiBleed #Fortinet #Payload
A reboot may not clear an infected device: Fortinet says ClingSTUN can persist on vulnerable routers, cameras and other connected devices.
Researchers hav…
Citrix NetScaler, FortiMail, Check Point, and MikroTik were all found under attack in one fortnight, mostly before a fix existed. Patching closes the door. It does not tell you who came through it first. Read the filing #citrix #fortinet #patching #infosec
FortiMail is meant to filter dangerous email for businesses.
CISA says a flaw in the product is already being used in attacks, and is urging organizations to check t…
CVE-2026-104286 is a FortiMail 0-day path traversal already being exploited—patch now. #Cybersecurity #Fortinet #ZeroDay #EmailSecurity #CVE2026 #KEV https://thedailytechfeed.com/critical-fortinet-fortimail-0-day-added-to-kev-after-active-exploitation/
Pentagon data, Apple & Fortinet zero-days exploited—patches and precautions urgent. #Cybersecurity #ZeroDay #DataBreach #AIsecurity #Fortinet #Apple https://thedailytechfeed.com/pentagon-breach-apple-fortinet-0-days-headline-26-major-cyber-threats/
Fortinet warns of critical zero-day (CVE-2026-104286) in FortiMail, actively exploited for RCE. CVSS 9.8. CISA added to KEV. Patches are pending, but urgent workarounds are available. #Fortinet #ZeroDay #CVE2026104286 #CyberSecurity
🌐 cyber[.]netsecops[.]io
#Fortinet warns of critical #FortiMail flaw exploited in zero-day attacks
Fortinet says Critical FortiMail zero-day CVE-2026-104286 is actively exploited.
The unauthenticated flaw can allow arbitrary file writes through crafted HTTP/HTTPS requests.
🚨 Fortinet sounds the alarm over actively exploited FortiMail zero-day
「 The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform 」
Fortinet alerts that its FortiMail zero-day is actively exploited; patch pending. #Fortinet #FortiMail https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803