FortiBleed Exploited: Tracking Initial Access Broker Dark_Alpha on Darkforums
Brief
July 15, 2026
Background: What Is FortiBleed?
In mid-June 2026, security researchers identified a large-scale credential compromise campaign targeting Fortinet FortiGate firewalls, quickly dubbed FortiBleed. Unlike a traditional zero-day, FortiBleed is not tied to a single new vulnerability.
Instead, threat actors systematically extracted configuration files from internet-facing FortiGate devices and cracked the stored password hashes — exploiting the fact that many organizations running older FortiOS versions continued to store administrator credentials as legacy SHA-256 hashes rather than the more secure PBKDF2 format Fortinet introduced in FortiOS 7.
- 11, 7.
- 8, and 7.
- 1.
Devices upgraded from earlier versions retain SHA-256 hashes until each administrator logs in post-upgrade, leaving a window of exposure that the campaign actively exploited at scale.
