After several days spent reverse-engineering the attacker’s environment, the SOCRadar research team has published a new, in-depth technical analysis on the FortiBleed campaign, including the attacker’s infrastructure, tooling, and methods.
Summary:
FortiBleed is a large-scale, still-active credential-harvesting campaign targeting internet-facing Fortinet FortiGate firewalls — hundreds of thousands of devices in scope worldwide. It is important to state plainly what it is not: this is not a zero-day or a newly disclosed software vulnerability. It is a credential and access operation. Attackers compromise exposed firewalls, harvest the authentication traffic and credentials passing through them, crack what they capture, and sell that access on. The actor fits the profile of a financially-motivated initial access broker — the kind whose intrusions become the front end of someone else’s ransomware or data-extortion event.
Why it matters — and the number to focus on. At the time of writing, more than 19,000 FortiGate devices were still being actively sniffed by the attackers — part of a broader 80,553 identified targets. That present tense is the point: this is not a historical data dump to clean up after, but a live operation, running since at least February 2026, quietly capturing authentication traffic as users log in each day. Because the firewall sits at the network edge, a compromise there can expose an organization’s entire identity layer — and the campaign reaches deep into supply chains, since MSPs and IT-services firms that manage Fortinet devices for others are squarely in the targeting.
What’s new in this report:
- A custom Golang tool (“FortigateSniffer”) that abuses a legitimate FortiOS diagnostic command to passively capture authentication traffic from a compromised firewall — leaving no malware behind and largely evading traditional detection.
- Targeting beyond Fortinet. The attacker’s own infrastructure contained reconnaissance/target lists for other edge platforms — a 29,270-entry Citrix login-URL list and roughly 247,584 Sophos SSL-VPN portals — showing the operation’s scanning was multi-vendor, not Fortinet-exclusive. (To be precise: these are targeting artifacts; we did not find captured credentials for the Citrix or Sophos tracks, so we characterize them as in-scope for reconnaissance rather than confirmed compromise.)
- Attacker infrastructure far larger than the single exposed server first reported — 150+ servers — plus the operators’ use of rented GPU compute and agentic tooling.
What goes deeper: The report maps the full attack chain end to end — reconnaissance, initial access, credential cracking, lateral movement into Active Directory, and exfiltration — with indicators of compromise, file hashes, a MITRE ATT&CK mapping, and the attribution clues pointing to a Russian-speaking access broker.
What it corroborates: Several findings independently align with other published research, which we think is worth noting rather than glossing over: the Sophos figure (~247,584) matches what others observed, as do the scale of the MSSQL brute-forcing and the confirmed deep intrusion at a defense contractor. Where the picture is still uncertain — full attribution, for instance — is noted as well.
To view the full report, see Dismantling FortiBleed: Inside a Russian Fortinet Compromise Operation

Rogers & Fido Customers See $4-$5 Increase…. Some Just Joined…. WTF?
Posted in Commentary with tags Rogers on June 22, 2026 by itnerdTruly from the WTF category comes this $4-$5 increase in their cellular bills from Rogers (five dollars) and Fido (four dollars). And to add insult to injury comes the fact that some people have joined as little as three months ago. Here’s what iPhone In Canada posted:
Rogers is adding a $5 monthly increase for select wireless customers, set to kick in on or after July 15, 2026. The justification mirrors what Fido told its own customers, a vague nod to network investment. The note on Rogers bills says the company continuously invests in its 5G network to deliver “Canada’s most reliable” experience, and that the monthly fee for affected plans is going up by $5 plus tax to help cover those costs.
Instead of just raising the plan price outright, Rogers is tacking the charge on as its own line item called Wireless Plan Rate Adjustment. That wording has already drawn criticism online, with some customers pointing out that breaking the fee out separately might be a way to get around price guarantees or fixed-rate promises.
What being talked about here is that the CRTC has hit the big three hard in terms of junk fees that stop people from moving carriers easier. So instead of explicitly calling out the fee increases, Rogers and Fido are instead shifting the prices around to bury them as much as possible so that they can’t be called out . Rogers for its part said this on their bill:
“We continuously invest to bring you Canada’s most reliable 5G+ network and the best mobile experience in Canada.”We continuously invest to bring you Canada’s most reliable 5G+ network and the best mobile experience in Canada. To help support these investments, the monthly fee (Monthly Charge) for your wireless price plan will increase by $5 (plus taxes), starting with your next bill, on or after July 15, 2026. This will appear as an additional line item under Monthly Charges on your monthly bill called Wireless Plan Rate Adjustment. The rest of your wireless services remain the same. If you have any questions or no longer wish to subscribe to your wireless service, please reach out to us as indicated in the Contact Us section of this bill.”
But people are not impressed. Some of which phoned me out of desperation. My advice is simple. Freedom Mobile hasn’t got the best coverage. But they have good enough coverage that for most people, their travels in the GTA are good enough. Ditto for many metropolitan areas as well. Plus they have done away with the junk fees that the CRTC is trying to ban. That on top of the fact that my last few trips overseas has seen a substantial reduction in roaming charges. While Freedom isn’t for everyone, that is a solution for Rogers (and ultimately TELUS and Bell) screwing customers over.
Just a thought.
Leave a comment »