Click any tag below to further narrow down your results
Links
Since February 2026, a Russian-speaking broker has run a mass credential-harvesting campaign against over 430,000 FortiGate firewalls using a Golang sniffer called FortigateSniffer and brute-force tools. Harvested cleartext passwords and hashes feed an automated pipeline for cracking, lateral movement and data exfiltration across SMBs, with operations geofenced and time-restricted to avoid detection.
CISA warns that a Russian-speaking threat actor has harvested 86,644 valid logins from internet-facing FortiGate firewalls and VPNs using SSL VPN interception, GPU-powered hash cracking, and brute-force attacks. Major government entities and critical infrastructure providers are affected. CISA advises resetting credentials, enforcing PBKDF2 for admin logins, enabling phishing-resistant MFA, and tightening management access.