Observed Signal · Jun 17, 2026 · Security Breach · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
Massive 'FortiBleed' Campaign Compromises Fortinet Devices
Two cybersecurity firms, Hudson Rock and SOCRadar, report an ongoing campaign dubbed "FortiBleed" that has compromised tens of thousands of Fortinet firewalls and VPN gateways worldwide. Attackers scan the internet for exposed Fortinet devices and use lists of previously leaked passwords to brute-force access; compromised devices are then used to harvest additional credentials and propagate further intrusions. Hudson Rock found evidence suggesting more than 73,000 unique Fortinet URLs were compromised, while SOCRadar reported over 30,000 affected devices. Reported victims include large enterprises such as Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens and PwC. Affected countries with the highest counts include India, the United States, Taiwan and Mexico. Fortinet responded saying the campaign is a third-party credential-harvesting activity and reflects reshared data and credential brute-forcing rather than a new Fortinet vulnerability.
Widespread compromise of enterprise network appliances used by major global companies risks data exposure, lateral movement, and operational disruption across affected sectors, including firms that support advertising and marketing operations.
Track Fortinet Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Hudson Rock reports evidence that more than 73,000 unique Fortinet URLs were compromised.
- SOCRadar reports the total of hacked Fortinet devices exceeds 30,000.
- Attackers scan for exposed Fortinet firewalls and VPNs and gain access using previously leaked passwords (credential brute-forcing/credential stuffing).
- Hudson Rock lists victims including Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens and PwC.
- Fortinet said the campaign is a third-party credential-harvesting campaign involving reshared data and bruteforcing, not a new vulnerability.
Connected Companies & Entities
7 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
FortiOS CVE-2025-68686 Symlink Mitigation Bypass
CVE-2025-68686 is an actively exploited FortiOS vulnerability that allows attackers who already have file-system access to bypass symlink persistence mitigations via crafted HTTP requests to the SSL‑VPN web interface. The flaw can expose sensitive files (configurations, credentials, keys) even after firmware upgrades. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026. Affected FortiOS versions include 6.4, 7.0, 7.2, 7.4.0–7.4.6 and 7.6.0–7.6.1; vendor fixes are available in 7.4.7, 7.6.2 or later. Successful exploitation requires a prior file‑system compromise; remediation guidance includes rebuilding devices, removing artifacts, rotating secrets, and restricting SSL‑VPN exposure.
Supply-chain attack compromises dozens of open-source packages
Cybersecurity researchers reported a large ongoing supply-chain attack that has compromised hundreds of open-source package versions across dozens of projects. StepSecurity and SafeDep warned that attackers hijacked a developer account and pushed more than 630 malicious versions spanning 317 npm packages in roughly 20 minutes. The malicious updates aim to harvest credentials — including from password managers — and to propagate further. Affected projects include Antv (a library associated with Alibaba); JFrog Security said some malicious updates were published via GitHub. Researchers call the campaign “Mini Shai-Hulud”; it follows an earlier wave that compromised the TanStack library and led to the computers of two OpenAI employees being breached. The incident underscores ongoing risks in open-source dependency security and rapid downstream exposure for developers and organizations that consume compromised packages.
Password-Stealing Malware Exposes 1,787 US Water Providers
New research from cybersecurity firm SpyCloud reveals that over a thousand U.S. water and wastewater providers are at risk due to password-stealing malware that compromised employee credentials and session tokens. The firm analyzed over 66,000 public-facing systems registered with the Environmental Protection Agency, identifying 1,787 organizations (nearly 20%) with stolen credentials, and at least 250 with credentials having potential access to operational networks. A case study of an unnamed metering tech provider found one infected device had leaked passwords for 167 utility companies. While this research did not link these exposures to the recent Iran-backed hacks, it underscores the vulnerability of critical infrastructure through infostealer malware and the trade of stolen credentials.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
