The FBI and Secret Service warned that FortiBleed, a credential-harvesting campaign against internet-facing FortiGate firewalls and SSL VPN gateways, remains active. The Russian-speaking operation uses credential stuffing and password spraying, then deploys a Go tool called FortigateSniffer to intercept authentication traffic, exploiting reused or leaked credentials and legacy SHA-256 password storage rather than a software flaw. It had collected more than 86,644 working device credentials across 194 countries as of June. Attackers create new admin accounts and reuse session cookies for persistence, and some victims are locked out when original accounts are changed or deleted. Operator overlaps link it to INC and Lynx ransomware.