Jun 23 · Industry News

FortiBleed: The Breach With No Bug

Today’s roundup centers on FortiBleed, a mass credential-harvesting campaign against internet-facing Fortinet firewalls, alongside a new ransomware EDR-killer toolkit, an exposed 24-billion-record credential database, and CISA’s new risk-based patching directive. Confidence levels and sourcing are noted throughout.

★ Top Read

“FortiBleed” is the breach with no new bug: attackers harvested working administrator and SSL-VPN credentials from internet-facing FortiGate firewalls at scale by cracking weakly hashed secrets pulled from device configs, and CISA has issued a hardening advisory.

Reported exposure ranges from roughly 74,000 devices, CISA’s figure, to 86,644, per vendor and researcher telemetry, across 194 countries. The common thread is old credential storage plus missing multi-factor authentication, not an unpatched CVE.

The lesson worth drawing: the perimeter device that’s supposed to enforce identity becomes the breach when nobody has visibility into how its own credentials are stored, reused, and authenticated against.

Sources: CISA, SecurityWeek, The Hacker News, Arctic Wolf, Recorded Future

Cyberattacks & Breaches

FortiBleed: roughly 74,000 to 86,000 FortiGate devices with compromised credentials. CISA confirmed on June 18 that threat actors are using leaked credentials against internet-accessible Fortinet firewalls and SSL-VPN gateways across government and private-sector networks. Researchers say the activity stems not from a new vulnerability but from extracting configuration files and cracking historically weak credential hashes, yielding verified working logins; counts vary by source, with Arctic Wolf and Recorded Future citing roughly 30,000 to 75,000 working credentials and The Hacker News citing 86,644 as of June 19. CISA’s guidance: immediately terminate all active SSL-VPN and admin sessions, reset all Fortinet VPN and admin passwords on internet-facing systems, and enforce multi-factor authentication.

So what: Today’s through-line is the credential, not the CVE. FortiBleed and the 24-billion-record dump below are both credential-exposure stories, and GentleKiller exists to blind the endpoint agent that would otherwise catch the follow-on. None of this is stopped by patching faster — it’s stopped by visibility across identity and authentication telemetry, and by not trusting a single control, such as the firewall or the EDR agent, to be both the enforcement point and the only thing watching it.

“The Gentlemen” ransomware-as-a-service ships a standardized EDR-killer suite to affiliates. ESET detailed GentleKiller, an eight-variant BYOVD (bring-your-own-vulnerable-driver) framework that disables more than 400 security processes across roughly 48 products by abusing vulnerable or malicious drivers, with each variant masquerading as a different legitimate tool. The operation also folds in third-party killers such as HexKiller, ThrottleBlood, and HavocKiller, and offers affiliates a 90% revenue share, centralizing defense evasion so affiliates don’t have to build it themselves — a model that has made Gentlemen one of 2026’s most active ransomware gangs. ESET’s research attributes leadership to a named Russian national; that attribution is ESET’s finding and has not been independently confirmed.

So what: Today’s through-line is the credential, not the CVE. FortiBleed and the 24-billion-record dump below are both credential-exposure stories, and GentleKiller exists to blind the endpoint agent that would otherwise catch the follow-on. None of this is stopped by patching faster — it’s stopped by visibility across identity and authentication telemetry, and by not trusting a single control, such as the firewall or the EDR agent, to be both the enforcement point and the only thing watching it.

Roughly 24 billion credential records found in an exposed database. Cybernews reported an 8.3 TB publicly exposed collection of approximately 24 billion username, password, and account records aggregated from about 36 sources, including Telegram channels, prior breach compilations, and infostealer logs, with some data apparently exported from live servers. This is a recompilation rather than a single new breach, so the headline number overstates novel exposure — the real signal is the continued industrialization of infostealer log aggregation.

So what: Today’s through-line is the credential, not the CVE. FortiBleed and the 24-billion-record dump are both credential-exposure stories, and GentleKiller exists to blind the endpoint agent that would otherwise catch the follow-on. None of this is stopped by patching faster — it’s stopped by visibility across identity and authentication telemetry, and by not trusting a single control, such as the firewall or the EDR agent, to be both the enforcement point and the only thing watching it.

Vulnerabilities & Exposure

Apple “usbliter8” SecureROM proof-of-concept goes public. A working proof of concept published June 18 for an unpatchable hardware flaw in the Synopsys DWC2 USB controller affects A12/A13/S4/S5-class Apple silicon — the iPhone XS through 11 era, iPad, and older Watch and HomePod mini models. Exploitation requires physical possession of the device, the right cable, and forcing DFU mode, which makes it low risk for typical users but turns affected hardware into a device-custody and hardware-retirement problem for high-security environments. As of disclosure there was no CVE, CVSS score, Apple advisory, or CISA alert, and no in-the-wild exploitation had been reported.

So what: Today’s through-line is the credential, not the CVE. None of today’s stories are stopped by patching faster — they’re stopped by visibility across identity and authentication telemetry, and by not trusting a single control to be both the enforcement point and the only thing watching it.

AI Impact on Security

Agentic-SOC tooling keeps moving from demo to default. SentinelOne opened Purple AI “Agentic Investigation” to all customers this week (June 17), pitching zero-click autonomous detect-investigate-verify-respond using a multi-model stack including Anthropic Claude, OpenAI GPT, and its own models, and introduced “Singularity Credits” as a consumption currency. It lands in the same lane CrowdStrike, Cisco, and Palo Alto staked out with agentic-SOC launches at RSAC 2026.

So what: The agentic-SOC race is now a feature-parity sprint at the vendor layer, which means the durable differentiator isn’t the agent — it’s the breadth and quality of the data the agent reasons over. An autonomous investigation is only as good as its visibility across distributed telemetry.

Regulatory & Policy

CISA issues Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk”. Federal civilian agencies must now triage vulnerability remediation against four criteria: asset exposure, known-exploited status, exploit automation, and post-exploitation impact. The most severe cases — publicly exposed assets with known-exploited, automatable bugs that grant total control — must be fixed within three days, with forensic triage to check for pre-patch compromise. Agencies get 60 days to revise processes and 180 days to meet timelines and continuously tag every externally reachable asset.

So what: This operationalizes a shift that’s been building for months: federal patching is now risk- and exploitability-driven, not fixed-SLA. A three-day clock is impossible to hit without continuous exposure and exploitation visibility, plus a live, tagged inventory of every internet-reachable asset.

← All Industry News