The Gentlemen, a ransomware group founded in early 2025 with access to 14,000 compromised FortiGate devices, has risen to become the world’s most active extortion…
Russian-speaking initial-access brokers have attacked at least 430,000 FortiGate firewalls with FortiBleed and harvested login credentials to gain access to corporate networks.
Attackers deploy a Golang-based sniffer on 430,000 compromised FortiGate firewalls to harvest 110 million credentials, transforming critical security devices into reconnaissance instruments.
Attackers exfiltrate FortiGate device configurations, crack SHA-256-hashed admin passwords offline, and gain administrative access without exploiting a new vulnerability.
FortiGate devices with enabled SSL-VPN were compromised through three critical vulnerabilities, allowing attackers to install backdoors and gain read access to file systems; up to…