Breach Watch: FortiBleed Locks Admins Out

Breach Watch: FortiBleed Locks Admins Out
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · October 7, 2026

TL;DR for CISOs: The FBI and Secret Service say FortiBleed attacks are still running and are locking administrators out of Fortinet firewalls, attackers hijacked three country-code registries to obtain certificates for Google domains, and the critical Atlassian flaw from yesterday is now being probed in the wild.

BOTTOM LINE FOR CISOS
  1. Patching and password resets may not be enough for Fortinet. Agencies say attackers create their own admin accounts and remove yours, so verify every account on the device, not only the credentials.
  2. Your domain's trust can be attacked above your own DNS. A registry-level compromise let attackers pass certificate validation. Certificate Transparency monitoring is the control that would have shown it.
  3. The gap between a published write-up and first exploitation is now measured in hours. If a critical flaw affects an exposed system, treat the advisory day as the deadline.

Lead story: FortiBleed attacks are locking administrators out of Fortinet firewalls

CRITICAL · ACTIVE CAMPAIGN
Key facts
Affected technology: Internet-facing Fortinet FortiGate firewalls and SSL VPN gateways
Advisory: A joint FBI and U.S. Secret Service advisory, released October 6, says the attacks are ongoing
Scale: SOCRadar counts 86,644 compromised devices across 194 countries. That figure is SOCRadar's, cited in the advisory and reported by BleepingComputer and Help Net Security. A separate figure of 73,932 firewall URLs relates to the June credential leak that gave the campaign its name
Method: Credential stuffing and password spraying using earlier leak dumps and infostealer logs, then offline cracking of password hashes taken from compromised devices on a GPU cluster
Impact on defenders: In some incidents attackers created new admin accounts, then deleted original admins or changed their passwords. The agencies describe these findings as based on initial responses
Ransomware link: The FBI describes the chain as an entry point for ransomware affiliates and names INC/Lynx and Payload. SOCRadar's link to INC and Lynx comes from its own analysis
Unknown: How the June configuration data was originally obtained

What happened

FortiBleed started as a credential leak in June, when an attacker server holding usernames and plaintext passwords for Fortinet devices was exposed. Four months later the FBI and Secret Service say the activity continues. Attackers are still scanning exposed firewalls with previously obtained credentials, pulling password hashes from devices they reach, and cracking them offline.

The new element is the lockout. Responders found that after entry, attackers created accounts of their own and in some cases removed or changed the legitimate ones. Reporting also describes attacker tooling that filters out honeypots and ranks targets by revenue and network structure. Help Net Security reports, without naming a source, that access is then sold to ransomware affiliates. BleepingComputer treats the access-for-sale point as an inference from exposed material, so treat it as unconfirmed.

Evidence

Verified against independently fetched sources:
1. BleepingComputer, FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
2. Help Net Security, FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
3. The Record, FBI, Secret Service add to warnings of FortiBleed credential stealing campaign

What this means for your team

If you completed a Fortinet password reset after the June warning, you may have closed only part of the exposure. The advisory points to persistence through accounts and to hashes that can be cracked later, so a reset performed before the attacker stole the hash does not help. The practical question is whether anyone can still log in who should not, and whether you would know.

The lockout detail also changes your incident planning. If an attacker removes your administrators, your recovery path needs an out-of-band option, such as console access or a vendor support route, that does not depend on the compromised credentials.

Action checklist

  1. List every FortiGate and SSL VPN gateway with an internet-reachable management or VPN interface, and remove management access from the internet where you can.
  2. Audit all local accounts on each device against your approved list, and review logs for admin accounts created or deleted since June.
  3. Terminate active VPN sessions, reset all credentials, enforce MFA, and follow the agencies' guidance to store admin passwords with PBKDF2 rather than legacy SHA-256 hashes.
  4. Confirm you have a documented out-of-band way to regain device control if administrators are locked out.

Attackers hijacked three country-code registries to obtain certificates for Google domains

HIGH · CONFIRMED BY GOOGLE
Key facts
Registries: .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa), through compromise of their third-party operators
What was done: Authoritative DNS records were changed, which let attackers pass domain validation and obtain valid HTTPS certificates for domains they did not own
Certificates: The Hacker News reports at least 12 certificates for Google and YouTube names between September 22 and 27, issued by Let's Encrypt and ZeroSSL and since revoked. It notes the search covered only a subset of names
Disclosure: Google published its response on October 6 and said its own systems were not compromised
Unknown: Who is responsible, how the registries were breached, whether any certificate was used against users, and the full list of affected organizations

What happened

Google said it learned of the hijacks the week before its disclosure. It blocked the unauthorized certificates in Chrome and worked with the issuing certificate authorities to revoke them. Certificate Transparency data showed other organizations were also affected, including large global brands that Google did not name.

Evidence

Verified against independently fetched sources:
1. BleepingComputer, Hackers hijack Google domains after breaching ccTLD registries
2. Help Net Security, Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains
3. The Hacker News, Attackers hijack .gh, .sl, and .as registries to obtain certificates for Google domains

What this means for your team

Most certificate controls assume DNS is trustworthy. Here the attacker controlled DNS for the name itself, so the certificate authority saw a legitimate validation. Chrome's blocking helped Google, but Google states that other browsers may not be covered, which means your customers and your own non-Chrome clients depend on revocation reaching them.

Regional and parked domains are the weak point. Many organizations register country-code variants defensively and then do not watch them.

Action checklist

  1. Inventory every domain you own, including parked and country-code variants, and check which registry operator each one depends on.
  2. Monitor Certificate Transparency logs for all of them and alert on any certificate you did not request.
  3. Publish restrictive CAA records, and know that they limit issuance but do not stop a certificate during an active DNS hijack.
  4. Pre-agree who reports an unauthorized certificate to the issuing authority and how fast.

Atlassian CVE-2026-21589 draws exploitation attempts within hours of public technical details

HIGH · EXPLOITATION OBSERVED
Key facts
Flaw: CVE-2026-21589, arbitrary file access without authentication, CVSS 9.3
Affected: Self-hosted Data Center editions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd, plus Crucible and Fisheye. Atlassian says its cloud products are patched
Observed activity: Previdian, a threat intelligence firm, saw exploitation attempts on its honeypots. The Hacker News counts 15 attempts from three IP addresses in Japan and the United States
Credential risk: In Crowd-integrated Jira deployments, researchers at watchTowr showed file reads can expose Crowd credentials and lead to a rogue Jira administrator
Differences in reporting: Sources disagree on whether working exploit code is public. All agree watchTowr published technical analysis and a scanner
Not reviewed: Whether CISA has added the flaw to its Known Exploited Vulnerabilities catalog

What happened

This follows yesterday's report that Atlassian had patched the flaw with no known exploitation. After watchTowr published its analysis, Previdian reported attempts against its sensor network, in one account within two hours. Atlassian has said it cannot tell whether individual customer instances have been compromised.

Evidence

Verified against independently fetched sources:
1. BleepingComputer, Hackers exploit critical Atlassian flaw after public PoC release
2. Help Net Security, Exploitation attempts against critical Atlassian flaw have begun
3. The Hacker News, Atlassian Data Center flaw draws exploitation attempts within two hours of public details

What this means for your team

Probing on a honeypot is not proof of compromise, but it tells you scanning has started. For internet-exposed instances, assume your patch window is now, and treat any instance you cannot patch today as one to take off the internet.

Action checklist

  1. Patch exposed Data Center instances to the fixed releases in Atlassian's advisory, or remove them from the public internet until you can.
  2. Where you cannot patch, apply Atlassian's published mitigations such as WAF or Tomcat rewrite rules and restrict Crowd to an IP allowlist.
  3. Review Crowd credentials, rotate them, and check Jira administrator group membership for accounts you did not create.
  4. Search web logs since October 6 for the request patterns in Atlassian's advisory and block the IP addresses Previdian published.

Southern Company customer portal breach affects about 400,000 utility accounts

NOTABLE · CONFIRMED BREACH
Key facts
Organization: Southern Company, including Georgia Power and Alabama Power
Scale: About 400,000 accounts. SecurityWeek reports roughly 300,000 at Georgia Power and 100,000 at Alabama Power
Data involved: Names, addresses, phone numbers, email addresses and the last four digits of Social Security numbers. Fox10 adds business tax IDs. The company says full SSNs, bank account numbers, payment cards and driver's license numbers were not involved
Disclosed: October 5, with SecurityWeek reporting on October 7
Unknown: When access began, how the attacker entered the portal, and who is responsible

What happened

Southern Company says an unauthorized third party reached its online customer portal and accessed limited account information. It says it stopped the activity, has found no evidence of ongoing access, is working with law enforcement, and is notifying customers and offering free credit monitoring.

Evidence

Verified against independently fetched sources:
1. SecurityWeek, Georgia Power, Alabama Power data breach hits 400,000 accounts
2. Fox10, Southern Company hit by data breach
3. WSB-TV, Cyberattack on Georgia Power exposed info of 400,000 customers

What this means for your team

The exposed fields are limited, but names, contact details and a partial SSN are enough for convincing phishing that references a real utility account. The missing entry point is the useful lesson: until the company explains it, every organization with a customer portal should ask whether its own login controls would catch the same kind of access.

Action checklist

  1. Review portal authentication for credential stuffing resistance, rate limits and anomaly alerts on bulk account lookups.
  2. Check which fields the portal returns after login and mask partial identifiers where the customer does not need them.
  3. Prepare customer messaging that anticipates impersonation phishing after any notification.

Also notable

  • SonicWall SMA1000: SonicWall patched a maximum-severity, pre-authentication server-side request forgery flaw (CVE-2026-102255) in SMA1000 appliances. SonicWall says it has no evidence of exploitation, and Shadowserver tracks over 400 exposed appliances. Sources: BleepingComputer and Help Net Security.
  • Advantest: The semiconductor test equipment maker confirmed personal information was stolen in a ransomware attack from earlier this year. Sources: BleepingComputer and SecurityWeek.
  • MonsterCloud: The owner of a ransomware recovery firm has been charged with secretly paying attackers while billing victims for recovery. Sources: BleepingComputer and Help Net Security.
  • Chrome 155: The update patches 247 vulnerabilities. Single source: SecurityWeek.
  • Yesterday's edition: the Arizona courts breach, the FBI contractor patch lapse and the first Atlassian advisory are in the October 6 briefing.

Frequently asked questions

What is FortiBleed?
FortiBleed is a credential-harvesting campaign against Fortinet FortiGate firewalls and SSL VPN gateways. It takes its name from a June leak of Fortinet usernames and passwords, and the FBI and Secret Service say it remains active.

How many devices are affected by FortiBleed?
SOCRadar counts 86,644 compromised devices in 194 countries, a figure cited in the agencies' advisory. It is a vendor count that the reporting did not independently confirm.

Is patching enough to recover from FortiBleed?
The agencies say remediation may need to go beyond patching and password resets. They advise verifying all accounts, terminating VPN sessions, restricting external management access and enforcing MFA.

What happened with the .gh, .sl and .as registries?
Google says attackers compromised the third-party operators of the three country-code registries, changed DNS records and obtained HTTPS certificates for Google domains and others. Google says its own systems were not compromised.

Is the Atlassian flaw CVE-2026-21589 being exploited?
Previdian reports exploitation attempts on its honeypots, and The Hacker News counts 15 attempts from three IP addresses. Atlassian says it cannot determine whether customer instances were compromised.

What should a CISO do first this week?
Audit Fortinet admin accounts and management exposure, patch or isolate Atlassian Data Center instances, and start monitoring Certificate Transparency logs for every domain you own.

CISO Platform Breach Intelligence Team
Curated by Pritha Aash, Community Head, CISO Platform

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

★
★
★
★
★
Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion