CRITICAL ⚡ MUST-KNOW
FortiBleed Attackers Use Golang Sniffer to Harvest 110 Million Credentials
A threat actor is running an ongoing credential-harvesting campaign against FortiGate firewalls using a custom Golang-based sniffer. The campaign has targeted roughly 430,000 FortiGate firewalls and captured an estimated 110 million credentials since at least February 2026. SecurityWeek attributes the activity to a Russian initial access broker, and the heists are described as still persisting. Organizations running FortiGate firewalls should audit for signs of credential sniffing and rotate any potentially exposed credentials.