The FortiBleed credential theft campaign has been connected to Lynx ransomware and the INC operation, indicating stolen Fortinet credentials are being weaponized for network intrusions.
Security researchers have established a direct link between the FortiBleed credential theft campaign and Lynx ransomware operations, along with activity tied to the INC group. The connection reveals that threat actors obtained Fortinet credentials through FortiBleed and are leveraging them to compromise networks.
FortiBleed refers to a widespread campaign targeting Fortinet systems to steal authentication credentials. The scale of the operation made it one of the largest credential theft efforts in recent months, affecting numerous organizations across multiple sectors.
The linkage to Lynx ransomware suggests the stolen credentials serve as an entry point for ransomware deployment. Threat actors typically use compromised credentials to establish initial access, move laterally through networks, and eventually deploy ransomware for extortion.
The involvement of the INC operation in this chain indicates coordination or overlap between different threat actors. Such connections are common in the ransomware ecosystem, where initial access brokers sell or share credentials with ransomware operators.
Organizations running Fortinet products are advised to audit their authentication logs and review access patterns for suspicious activity. Standard mitigation measures include implementing multi-factor authentication, resetting credentials for potentially compromised accounts, and monitoring for lateral movement within networks.
The discovery underscores the critical importance of credential security. Stolen authentication details remain among the most valuable assets for attackers, offering a direct pathway to internal networks without triggering initial compromise detection systems.
Fortinet has not yet issued specific guidance regarding this threat linkage. Organizations should monitor vendor advisories and coordinate with their security teams to assess exposure and remediation priorities.
Hacking group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. Security researchers confirmed the breach included detailed customer, booking, and travel records.
Multiple extensions in the Chrome Web Store and Microsoft Edge delivered malware that stole cryptocurrency, browser data, and user history while injecting fraudulent ClickFix lures.
A new survey reveals strong public opposition in the UK to government surveillance of encrypted communications. The findings highlight growing concern over privacy rights as lawmakers continue debating message scanning proposals.
PaperCut has released a second emergency security update for its NG and MF print management software after researchers discovered bypass methods for the initial fixes. The vulnerabilities are currently being exploited in the wild.