FortiBleed: 430,000 Firewalls Quietly Became Credential Vending Machines

FortiBleed: 430,000 Firewalls Quietly Became Credential Vending Machines

A firewall has exactly one job: stand at the door and keep the bad guys out. So there's a special kind of irony when the firewall itself becomes the bad guy's favorite eavesdropping device. Meet FortiBleed, the breach that turned the bouncer into a wiretap.

One Diagnostic Command, 110 Million Credentials

Security researchers disclosed FortiBleed, a sprawling credential-harvesting campaign that has compromised more than 430,000 FortiGate firewalls and siphoned over 110 million credentials directly from live network traffic since at least February 2026. CISA issued an alert urging organizations to harden their Fortinet devices.

The clever, infuriating part: the attackers' Go-based tool, "FortigateSniffer," abuses FortiOS's built-in "diagnose sniffer packet" command to passively capture authentication traffic across 24 protocols. It quietly parses out RADIUS, NTLM, and Kerberos material — no flashy exploit, just a legitimate diagnostic feature turned into a 659-pipeline harvesting operation.

When the Watchtower Joins the Enemy

Credentials skimmed straight from the wire are the gift that keeps on giving: they unlock VPNs, admin panels, and lateral movement deep inside networks, often without tripping a single alarm. Researchers have already confirmed at least one breach of a NATO-aligned defense contractor, with sensitive data exfiltrated afterward.

The point most coverage glosses over: this didn't require a zero-day. It weaponized a feature that was always there, operated by a financially motivated Russian-speaking access broker. The scariest attacks aren't the exotic ones — they're the ones that use your own tools against you while looking completely normal in the logs.

If you run FortiGate gear: rotate credentials, enforce MFA, and get those management interfaces off the open internet. Your firewall might be moonlighting.

Source: Dark Reading