What We Know
REST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gapsREST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gaps
Older than 2 weeksJust now

FortiBleed credential-theft campaign linked to Lynx ransomware

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Older than 2 weeks

What We Know

Security reporting says the FortiBleed operation harvested credentials from Fortinet FortiGate devices at scale, with investigators noting organizations in roughly 150 countries were targeted and claims that roughly 430,000 FortiGate devices were exposed. Attackers used that foothold in customer firewalls to steal credentials and gain further access into victim environments.

Multiple analysts and vendors have tied the harvested access to active monetization by ransomware groups: the INC Ransom family and the Lynx ransomware operation have been observed using FortiBleed-derived access to compromise domains and deploy ransomware. Reporting describes the campaign as organized and tiered, with actors beginning to “pile on” additional exploits such as a Nextcloud zero-day to expand intrusion and exploitation opportunities.

Source Comparison

Aligned reporting
6 corroborates - 2 adds context - 0 conflicts

Corroborates