fortinet2 articles
CISA Confirms Active Exploitation of Critical FortiSandbox Bugs — Patch Now or Pull the Plug
CISA has added two critical FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-25089), both scoring 9.1, to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The OS command injection flaws allow unauthenticated attackers to execute arbitrary commands via crafted HTTP requests, with fixes already released by Fortinet in April and June. CISA also flagged a critical Microsoft SharePoint Server deserialization flaw (CVE-2026-58644, CVSS 9.8), which enables authenticated attackers with Site Owner privileges to remotely execute arbitrary code.
FortiBleed Gang Moonlights for INC and Lynx Ransomware as Credential Haul Reaches 110 Million
The FortiBleed credential theft campaign has been directly linked to INC and Lynx ransomware operations, with an operator found accessing negotiation panels for both groups while using stolen FortiGate credentials to facilitate ransomware deployments. SOCRadar's investigation revealed the campaign targeted around 430,000 FortiGate firewalls globally, harvesting over 110 million credentials, with at least 12 confirmed ransomware deployments resulting in hundreds of encrypted endpoints. Evidence suggests the operation is run by an approximately 20-person Russian-speaking group, likely acting as an initial access broker, with signs they may be expanding their targeting beyond Fortinet devices to Citrix infrastructure.