:

FORTIBLEED CAMPAIGN WEAPONIZES CUSTOM FORTIGATE SNIFFER

AI DESK1 MIN READ
MON, JUN 22, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Security researchers have identified a large-scale attack campaign targeting Fortinet FortiGate devices using custom sniffer tools to harvest authentication credentials from compromised firewalls.

SOCRadar's analysis of the FortiBleed campaign reveals attackers deployed specialized packet sniffing software on vulnerable FortiGate appliances to intercept and extract login credentials and other authentication secrets. The campaign demonstrates a sophisticated approach to lateral movement, where compromised firewalls become staging points for credential theft. By deploying custom sniffers directly on network infrastructure, attackers gain access to plaintext authentication data passing through the device. FortiGate devices are widely deployed across enterprise networks as primary security perimeters, making them high-value targets. The FortiBleed campaign appears designed for large-scale reconnaissance, harvesting credentials that could enable further network penetration. Organizations running FortiGate appliances should verify patch levels immediately, monitor for suspicious process execution on devices, and review authentication logs for signs of compromise. The attack highlights the critical importance of securing administrative access to network infrastructure and implementing network segmentation to limit credential exposure.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

More than 50 ads containing AI-generated child sexual abuse material appeared on Facebook, Instagram, Messenger, and Threads, with some running as recently as this week, according to Meta's ad library data.

JUST NOWAI Desk

AI-generated phishing infrastructure is evolving faster than blocklists can track, rendering domain-based security strategies obsolete. Browser-level detection focused on attack techniques offers a more effective defense.

2H AGOAI Desk

Google Blogger has locked and deleted hundreds of blogs following a false positive that incorrectly flagged them for malware violations. The error affected sites across the platform without warning.

2H AGOSecurity Desk

A vulnerability in WebKit allows IP addresses and DNS queries to bypass proxy browsers and Apple's iCloud Private Relay, undermining privacy protections for users relying on these services.

7H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.