There’s no CVE here, and that’s the point. FortiBleed isn’t a new FortiOS bug. Per the advisory, it runs on reused or leaked credentials plus a legacy SHA-256 password storage scheme that lets the crew crack harvested hashes at scale. Fortinet said in June it believes the activity reuses credentials from earlier incidents (FG-IR-26-060 and FG-IR-25-647) and brute-forces devices with weak passwords and no MFA. So a box that’s fully patched can still be owned. The firmware update was never the fix.
How the operation runs. The crew exposed its own backend server, which is how researchers (CloudSEK, cited in the advisory) saw the whole pipeline. They scan for FortiGate SSL VPN portals, spray and stuff credentials from old Fortinet leak dumps and infostealer logs, dump FortiOS user databases and session tokens off devices they get into, and push the hashes through a rented GPU cluster running Hashcat and Hashtopolis. Then they filter out honeypots, rank targets by revenue and network size, add their own admin accounts, enumerate Active Directory, and package working VPN configs for sale. That’s an access broker, not a smash-and-grab crew.
Why the lockout matters. The agencies say plainly that remediation now goes “beyond standard patching and password resets.” If the attacker deleted or changed your original admin account, you may need console access or a vendor-assisted recovery to get your own perimeter back, during an intrusion that may already be moving laterally. Plan for that before you need it.
What we’d do this afternoon. Pull internet-facing management off every FortiGate. The advisory ranks it: trusted hosts is good, a local-in policy is better, and no internet admin at all is best. Kill every active admin and SSL VPN session, reset all VPN and admin passwords, and enforce phishing-resistant MFA on every external gateway and admin interface. Confirm admin credentials are stored with PBKDF2 and the legacy hashes are gone (Fortinet’s guidance covers FortiOS 7.2.11 and later). Diff configs against a known-good baseline and hunt for accounts you didn’t create. The advisory lists names seen on victim boxes, including forticloud-sync, forticloud-tech, fortiAdmin, adminsslvpn, support_fortinet, fgtsec, itadmin and Technical_support. They’re picked to look like vendor or IT accounts. Review and rotate every REST API key, and check whether SSH was open on the firewall, because the agencies say it may have been abused. Run the advisory’s IP list against firewall, VPN, auth and domain controller logs back to mid-June. It includes C2 45.154.12.132 and the 87.251.64.x and 185.136.15.x ranges. The agencies caution that these IPs may have been reassigned since, so vet them before you block.
The buyer read. Days after Citrix disclosed its third exploited NetScaler zero-day in under a week, the edge appliance is the story again, and the lesson isn’t vendor-specific. Firewall and VPN admin planes exposed to the internet, protected by passwords that leak, are an access-broker inventory. Expect renewal conversations to lean harder on ZTNA, on moving device management behind identity-aware access, and on identity threat detection that watches network-device admin logins, not just Entra and Okta.
Desk sheet: FBI + USSS joint advisory JCSA-20261006-01, Oct 6, 2026; FortiBleed credential campaign against FortiGate firewalls and SSL VPN gateways ongoing; 86,644+ compromised devices across 194 countries (SOCRadar, via the advisory; CISA’s June 18 alert cited about 74,000); lockouts via deleted or changed admin accounts; access passed to INC/Lynx and Payload affiliates; no new CVE. Named victims and number of ransomware incidents: Undisclosed.
