← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJul 15, 2026 · 10:00via DarkOwl

FortiBleed Exploited: Tracking Initial Access Broker Dark_Alpha on Darkforums

Brief

July 15, 2026

Background: What Is FortiBleed?

In mid-June 2026, security researchers identified a large-scale credential compromise campaign targeting Fortinet FortiGate firewalls, quickly dubbed FortiBleed. Unlike a traditional zero-day, FortiBleed is not tied to a single new vulnerability.

Instead, threat actors systematically extracted configuration files from internet-facing FortiGate devices and cracked the stored password hashes — exploiting the fact that many organizations running older FortiOS versions continued to store administrator credentials as legacy SHA-256 hashes rather than the more secure PBKDF2 format Fortinet introduced in FortiOS 7.

  • 11, 7.
  • 8, and 7.
  • 1.

Devices upgraded from earlier versions retain SHA-256 hashes until each administrator logs in post-upgrade, leaving a window of exposure that the campaign actively exploited at scale.

Read more on DarkOwl