A dataset dubbed 'FortiBleed' has exposed plaintext credentials for nearly 74,000 Fortinet FortiGate firewall and VPN devices across 194 countries — roughly half of all Fortinet firewalls exposed to the internet. The attack involved no zero-day exploit; instead, attackers used credential stuffing and brute-force techniques at massive scale, including a 45-GPU cluster running over a billion login attempts. High-profile organizations including Oracle, Samsung, Siemens, and a NATO defence contractor appear in the data. At least four organizations were fully compromised, with classified documents stolen from one. Fortinet disputes the data represents a new incident, but researchers say the affected devices differ from prior known leaks. Recommended mitigations include rotating passwords, enforcing MFA, restricting management interfaces to trusted IPs, and auditing logs.