Return to Threats

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

thehackernews.com 2026-10-07 data leakage Critical

What Happened

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat

Why It Matters

The report describes an active FortiBleed campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, with more than 86,644 devices reportedly compromised across 194 countries. Attackers harvested credentials through credential stuffing, password spraying, and interception of authentication traffic. The article does not identify an AI-specific system or impact; under the provided fallback classification, RealGround analysis maps the credential exposure and access-control risks to data leakage, security readiness, business-logic review, and executive security advisory services.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to data leakage. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.html

Talk to AI CISO