A large-scale credential-harvesting campaign called 'FortiBleed' has been uncovered, targeting over 430,000 internet-facing FortiGate firewalls by exploiting CVE-2026-35616 (CVSS 9.1) in FortiClient EMS. Attributed to a Russian-speaking initial access broker, the campaign deployed a custom Golang packet sniffer ('FortigateSniffer') on ~12,000 devices to passively intercept authentication traffic across 24 protocols, amassing over 110 million credentials. The operation is directly linked to INC Ransom and Lynx ransomware-as-a-service groups, with at least 12 confirmed ransomware deployments. Immediate mitigations include upgrading FortiClient EMS to 7.4.7+, rotating all credentials, auditing for the 'adminin' backdoor account, restricting port 8013, and enabling MFA on FortiGate admin interfaces.

4m read timeFrom orca.security
Post cover image
Table of contents
About FortiBleedAbout CVE-2026-35616Affected SystemsRisk ImpactHow Orca Can Help
117 Impressions