CVE Tools
Back to feed
Exploited in the wild FortiGate ransomware Fortinet

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

The FortiBleed campaign, which focuses on harvesting credentials from exposed Fortinet FortiGate systems, has been linked by SOCRadar to INC and Lynx ransomware operations—suggesting stolen logins were used for follow-on intrusions. The activity involved probing roughly 11,250 FortiGate portals, gaining admin access on 409 targets, and completing the attack chain on 354, leading to at least 12 ransomware deployments and widespread endpoint encryption. Separately, eSentire reported active exploitation of Fortinet FortiClient EMS vulnerabilities tied to CVE-2026-35616 (CVSS 9.1), enabling deployment of EKZ Stealer to harvest browser credentials.