Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

14 / 45 results
Active filter:vendor: fortinet✕ clear
Fortinet patches multiple high-severity vulnerabilities, urgent action neededhighbug_reportVulnerability
bug_reportVulnerability

Fortinet patches multiple high-severity vulnerabilities, urgent action needed

Multiple Fortinet products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. Organizations using Fortinet infrastructure should consult vendor security bulletins for detailed scope.

Fortinet28 Jul · 17:37 UTC
FortiBleed campaign targets Fortinet globally; Finland unaffectedhighbug_reportVulnerability
bug_reportVulnerability

FortiBleed campaign targets Fortinet globally; Finland unaffected

Fortinet products (specific models and versions not disclosed). Campaign active globally as of June 2026, Finland not impacted to date.

Fortinet23 Jul · 06:15 UTC
Fortinet FortiSandbox critical RCE and privilege escalation flawcriticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox critical RCE and privilege escalation flaw

Fortinet FortiSandbox - specific affected versions not disclosed in available advisory. Product used for malware analysis and threat detection in enterprise environments.

Fortinet17 Jul · 13:35 UTC
CISA orders patching of actively exploited Fortinet FortiSandbox flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Fortinet FortiSandbox flaws

Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.

Fortinet17 Jul · 05:03 UTC
FortiBleed Campaign Linked to INC and Lynx Ransomware Operationshighperson_alertThreat Actor
person_alertThreat Actor

FortiBleed Campaign Linked to INC and Lynx Ransomware Operations

The FortiBleed campaign is a financially-motivated credential theft operation attributed to actors associated with the INC and Lynx ransomware groups. The campaign focuses on exploiting FortiGate devices to harvest credentials, which are subsequently…

Fortinet2 Jul · 06:00 UTC
INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Theft

INC and Lynx are ransomware threat actors linked to the FortiBleed credential theft campaign. These groups operate with the primary motivation of financial gain through ransomware deployment.

Fortinet1 Jul · 19:37 UTC
Ousaban banking trojan targets Spain and Portugal via phishinghighbug_reportVulnerability
bug_reportVulnerability

Ousaban banking trojan targets Spain and Portugal via phishing

Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…

Fortinet1 Jul · 13:26 UTC
FortiBleed: Russian IAB harvests 110M credentials from FortiGate devicescriticalperson_alertThreat Actor
person_alertThreat Actor

FortiBleed: Russian IAB harvests 110M credentials from FortiGate devices

FortiBleed is attributed to a Russian-speaking initial access broker (IAB) conducting large-scale credential harvesting operations since February 2026. The actor demonstrates advanced operational capabilities through systematic targeting of over 430,…

Fortinet23 Jun · 16:20 UTC
FortiBleed Campaign Targets FortiGate Devices with Credential Sniffershighperson_alertThreat Actor
person_alertThreat Actor

FortiBleed Campaign Targets FortiGate Devices with Credential Sniffers

FortiBleed is a campaign-level designation for coordinated activity targeting Fortinet FortiGate network security appliances. The campaign's primary objective is credential harvesting through the deployment of custom sniffers on compromised firewalls…

Fortinet22 Jun · 18:01 UTC
Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleedhighperson_alertThreat Actor
person_alertThreat Actor

Russian-speaking actors compromise 86,644 FortiGate devices via FortiBleed

Russian-speaking threat actors are conducting the FortiBleed campaign, targeting internet-accessible FortiGate appliances at scale. The actors' specific motivation remains unclear from available data, though the mass compromise of 86,644 devices sugg…

Fortinet19 Jun · 12:00 UTC
CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leakhighpublicGeopolitical
publicGeopolitical

CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak

The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.

Fortinet19 Jun · 04:47 UTC
NCSC warns of active global campaign targeting Fortinet firewalls and VPNshighbug_reportVulnerability
bug_reportVulnerability

NCSC warns of active global campaign targeting Fortinet firewalls and VPNs

Fortinet firewalls and VPN gateways globally. Specific product lines and versions not disclosed in alert. Organizations using FortiGate, FortiOS, or FortiClient VPN services should assume potential exposure.

Fortinet18 Jun · 10:00 UTC
Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1criticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox under active exploit for 3 CVEs including critical 9.1

Fortinet FortiSandbox - specific affected versions not disclosed. Three CVEs: CVE-2026-39813 (CVSS 9.1 critical), CVE-2026-39808, CVE-2026-25089. At least one vulnerability recently patched; patch status of others unclear.

CVE-2026-2508916 Jun · 08:30 UTC
Active exploitation of critical FortiSandbox vulnerabilitiescriticalbug_reportVulnerability
bug_reportVulnerability

Active exploitation of critical FortiSandbox vulnerabilities

Fortinet FortiSandbox cyber threat detection platform. Specific versions not disclosed. No CVE assigned yet.

Fortinet16 Jun · 07:19 UTC