FortiBleed has exposed Fortinet VPN credentials for 73,932 unique firewall URLs across 194 countries. The leak reveals a large-scale Russian-speaking group's brute-force and cracking operation that fully compromised multiple organizations including a NATO contractor.

The operators reportedly captured SSL VPN authentication hashes, broke them with a 45-GPU cluster coordinated via Hashtopolis, and leveraged the resulting credentials for lateral movement inside Active Directory networks.
The credentials included numerous lengthy and intricate passwords normally viewed as resistant to cracking.
Enterprises using FortiGate SSL VPNs should immediately audit and rotate credentials while enabling multi-factor authentication, as the scale of verified compromises suggests lateral movement risks remain active.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
CISA added CVE-2026-104286 in Fortinet FortiMail to its Known Exploited Vulnerabilities catalog on October 1, confirming active exploitation. Mitigations must be applied by October 4 or discontinue use where fixes are unavailable.
Meta has paused its Model Capability Initiative AI training program after sensitive employee data including private conversations and performance metrics became visible to the entire company. The incident adds to a string of recent AI-related cybersecurity issues and is expected to heighten controversy around the firm's employee-monitoring practices.
Defused reports active exploitation of three critical FortiSandbox vulnerabilities that Fortinet patched on April 14. The issues permit unauthenticated attackers to achieve remote code execution and privilege escalation via simple command injection, continuing a pattern of Fortinet products targeted by ransomware and espionage actors.
GlobalFoundries signed a multi-year US$2 billion agreement with TSMC on October 8, 2026 to manufacture silicon interposers at its Malta, New York fab. The deal creates the first US-based source of silicon interposers for TSMC's CoWoS advanced packaging ecosystem.
SpaceX has agreed to acquire Grain Management's nationwide 800 MHz spectrum portfolio, which it says will pave the way for Starlink Mobile to become a major US mobile carrier. The deal needs FCC approval, and financial terms were not disclosed.