September 10, 2026
- Fortinet patched an unauthenticated authentication bypass in FortiMonitorOnSight plus a flaw in the Privileged Access Agent browser extension where any visited site could reconfigure the agent's proxy and observe the user's tab (SecurityWeek, research write-up).
· Exploited in the Wild
in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon
August 23, 2026
- fortitool decrypts and unpacks FortiOS firmware end to end as a single static Go binary — no OpenSSL, no binwalk, no Python dependency chain. Useful if you spend time diffing Fortinet images for patch analysis (@_n0p_ via @thegrugq).
· New Tools & Releases
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick
August 5, 2026
- QuickFox supply-chain attack deploys the FDMTP implant. FortiGuard Labs is tracking a long-running campaign — active since at least August 2025 — that trojanizes the QuickFox VPN/game-accelerator via a modified Electron renderer that fingerprints victims and loads a JavaScript stager (Fortinet).
· Supply Chain
in Frontier AI Agents Broke Containment and Attacked Real Targets During UK Government Testing
July 27, 2026
- A signed FortiClient kernel driver exposes a communication port for local privilege escalation. The port allows unprivileged process termination (DoS) and opens paths to credential theft, with mitigations still pending from Fortinet (write-up).
· Vulnerabilities & Exploits
in Two Live Exploits and a Bench of Fresh Offensive Tooling
July 18, 2026
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 2, 2026
A 19-year-old Scattered Spider member was extradited from Finland to face charges linked to 100+ intrusions and ~$100M in ransom payments. DuneSlide critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549) allow arbitrary command execution on developer machines with no approval. Huntress detected a massive Azure CLI password-spray campaign with 81 million login attempts compromising at least 78 Microsoft accounts across 64–78 organizations, exploiting OAuth ROPC to bypass MFA. DeepSeek was jailbroken into building working in-browser ransomware using the File System Access API, and Claude Desktop hijacking can yield remote code execution, underscoring critical security gaps in agentic AI tools.
June 24, 2026
Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.
June 23, 2026
- FortiBleed update: custom FortiGate sniffers and 86k confirmed creds — SOCRadar reports the campaign deployed custom sniffers on compromised firewalls to harvest authentication secrets, and Unit 42 frames it as broad password spraying against Fortinet, Sophos, and MSSQL using a curated list built from prior breaches; Fortinet says ~86,000 working credentials were validated. BleepingComputer · SecurityWeek
· Threat Activity
in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces
June 21, 2026
- FortiBleed has compromised credentials tied to 86,644 FortiGate firewalls and SSL-VPN gateways — about half of all internet-accessible Fortinet devices — in a campaign CISA, NCSC-UK, and CERT.dk all flagged this week (The Hacker News, CISA). Researcher Volodymyr Diachenko, who broke the story, traced an open directory showing SSL-VPN auth intercepted at scale, ~1.16 billion credential attempts against 320,000+ FortiGate targets (plus 2.1 billion against 160,000+ MSSQL servers), offline hash-cracking on a GPU cluster, and plaintext reuse for lateral movement into Active Directory — with at least four full compromises including a NATO defense contractor (Hunt.io via Florian Roth).
· Credential Theft & Initial Access
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
- FortiBleed has compromised credentials for ~86,644 internet-facing FortiGate firewalls and SSL VPN gateways — about half of all exposed Fortinet devices — prompting CISA, NCSC-UK, and CERT.dk to issue hardening advisories. Researcher Volodymyr Diachenko, who broke the story, documented SSL VPN authentication intercepted at scale, offline GPU hash-cracking, ~1.16 billion credential attempts against 320,000+ FortiGate targets (plus 2.1 billion against 160,000+ MSSQL servers), and plaintext reuse for lateral movement into Active Directory — with at least four full compromises including a NATO defense contractor. The Hacker News, CISA, BleepingComputer
· Initial Access & Credential Theft
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
- FortiBleed exposed working SSL-VPN credentials for roughly 70,000–74,000 internet-facing Fortinet firewalls and VPN gateways across ~194 countries, prompting urgent hardening advisories from CISA and the NCSC-UK (CISA, BleepingComputer). Researcher Volodymyr Diachenko traced the operation — surfaced via Hunt.io open-directory intel — to a Russian-speaking group intercepting SSL-VPN auth at scale, cracking hashes offline on a GPU cluster (~1.16B attempts against 320K+ FortiGates, plus 2.1B against 160K+ MSSQL servers), and reusing plaintext creds for Active Directory lateral movement; at least four orgs including a NATO defense contractor were fully compromised (Dark Reading). Rotate VPN credentials and hunt for post-auth AD access now.
· Threat Activity & Intrusions
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk
June 18, 2026
- Fortinet FortiSandbox is under active attack via three critical bugs — CVE-2026-39813, CVE-2026-39808, CVE-2026-25089 (path traversal + privesc, CVSS 9.1) — with CERT.dk flagging the attacks for Nordic defenders. Upgrade immediately (The Register).
· Vulnerabilities & Exploits
- FortiBleed — SOCRadar uncovered an industrialized credential-harvesting operation against Fortinet firewalls/VPNs: ~30,791 compromised devices, 8,316 organizations, across 194 countries, with attacker tooling, automation, and a verified-credential database recovered. Notably not a new zero-day — it's reused/leaked credential abuse at scale, so rotate creds and audit admin access (BleepingComputer, Dark Reading).
· Threat Activity & Ransomware
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel
June 17, 2026
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists