// NEXUSVOID CYBER NEWS

<- ALL CYBER NEWS

Critical

Fortinet, FortiGate, ransomware, credentials, INC, Lynx

FortiBleed: Credentials From Hundreds of Thousands of FortiGate Firewalls Now Fueling INC and Lynx Ransomware

Researchers link the FortiBleed credential-theft campaign to active ransomware operations: credentials harvested from hundreds of thousands of FortiGate firewalls are being used by the INC and Lynx ransomware groups for initial access.

Stolen credentials do not expire on their own. They sit in an access broker's inventory, sometimes for months, until someone with a use for them comes along. That is the second act now playing out with a campaign known as FortiBleed.

As SecurityWeek reports, credentials harvested from hundreds of thousands of FortiGate firewalls are being used to fuel ransomware attacks by the INC and Lynx operations, with The Hacker News corroborating the link between the credential theft and those two groups. The firewall meant to protect the perimeter has become the mine that hands attackers the keys to it.

This is the uncomfortable pattern of 2026's ransomware wave. Edge security devices, firewalls and VPNs, are prized precisely because they are both exposed to the internet and trusted deep inside the network. And a stolen credential defeats the usual mental model of patching, because the problem is not a missing update. It is valid access sitting in the wrong hands. An organization that patched its FortiGate after an earlier advisory but never rotated the credentials that were already taken has not actually closed the door.

So the response has to go beyond the patch. Rotate every credential that touched affected FortiGate appliances, admin accounts, VPN users, LDAP bind accounts, and reissue any certificates stored on the device. Then hunt: review VPN and admin logins since the exposure window for connections from unfamiliar places, and enforce multi-factor authentication on every remote-access path, because a stolen password is exactly the thing it exists to stop.

Sources: SecurityWeek and The Hacker News.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.