decrypted · 8 october 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security
FortiBleed is still locking admins out of their own firewalls, and the NCSC saw it coming
The FBI and US Secret Service warned this week that FortiBleed, a credential-theft campaign against Fortinet FortiGate firewalls and VPN gateways, is still running and is now locking administrators out of their own devices. The NCSC flagged it in June, saying there were "some indications of potential impact in the UK". What is new is the joint advisory of Tuesday 6 October: the stolen access is being passed to ransomware affiliates. The uncomfortable part is that nobody needs a vulnerability for any of this.
A front door with a guessable key
Think of a firewall as the reinforced front door of your network. FortiBleed does not break the door. It tries keys that have already leaked: passwords reused from earlier breaches, or lifted from infostealer malware on staff laptops. Attackers spray those at internet-facing VPN portals, and once one works they pull out the device's stored password hashes. A hash is a scrambled fingerprint of a password. The agencies say Fortinet's legacy SHA-256 storage lets those fingerprints be cracked offline, on a bank of graphics cards, where no alarm can ring.
The operators then create their own administrator accounts. Sometimes they delete the real ones or change their passwords, so the owner cannot get back in. The advisory also says that recovering from this takes more than patching and a password reset.
What the numbers do and do not say
The headline figure is 86,644 compromised devices across 194 countries. That count belongs to the security firm SOCRadar, which the agencies cite; it is not their own tally. The agencies say initial access brokers have offered access to affiliates of the INC/Lynx and Payload ransomware groups. SOCRadar reported in July at least 12 confirmed ransomware attacks from this access. The operation only became visible because the criminals exposed their own backend server.
What a defender sees, and what the fix costs
Unauthorised account creation and unexpected log activity are the NCSC's indicators. If you are locked out, you already know. Its guidance is practical:
- Check your domains against the FortiBleed checkers it names, and confirm each device is yours.
- If compromised, isolate the device, collect logs, then factory reset it, because changing credentials may not remove persistence.
- Investigate other edge devices sharing the same credentials.
- Keep management interfaces off the internet, enforce multi-factor authentication on every VPN and management login, and enable PBKDF2 for administrator accounts.
The Secure by Design lesson
Two design decisions did the damage. First, administration reachable from the whole internet: a management page should be reachable only from a trusted network. Second, password storage that is cheap to crack unless each customer finds the setting and changes it. Secure by Design means the safe setting ships switched on, not buried in a hardening guide. Applying it should cost little more than an afternoon per device: restrict administration to an allow-list, switch on PBKDF2, rotate every administrator password.
For a UK director the question is simple: who owns each firewall, who can reach its admin page, and would anyone notice a new account? If you cannot answer in a minute, you have your homework. The NCSC's free Early Warning service is a sensible place to start. This is opinion, not advice.
Also this week
Exposed AI servers are becoming botnet nodes. Lumen's Black Lotus Labs published research on 7 October on PoeLLM, malware that infects internet-facing AI and developer tools including LiteLLM, Ollama, Gotenberg and Gitea, then mines cryptocurrency and scans for more victims. Lumen's own report gives both almost 2,200 and more than 3,400 servers, and does not reconcile the two. It links the spread partly to CVE-2026-42271, a LiteLLM command injection flaw. The clever part is the control channel: the malware reads a poem on GitHub, picks four words from it and converts them into the IP address it should call, so the operator moves infrastructure by editing prose. The dull part is the cause. Self-hosted AI tooling went onto the internet without anyone treating it as a system that needs owning, patching and firewalling. Lumen's advice is to include AI tools in attack surface management and patch cycles. Quite so.
Teams will flag deepfakes, if you pick a provider. Microsoft's roadmap lists third-party deepfake detection and impersonation warnings for Teams meetings, both in development with general availability targeted for November 2026. Microsoft says certified providers do the detection and Teams surfaces the signal, so choosing, contracting and assessing that provider falls to you. Neither the roadmap nor the coverage names the launch providers or says whether it will be on by default. For UK organisations the questions are the usual ones: where meeting audio and video is processed, under what contract, and who is the controller. A sensible control, arriving with a new supplier attached.
Sources
- NCSC: Advice following global targeting of Fortinet firewalls and VPN gateways
- The Record: FBI, Secret Service add to warnings of FortiBleed credential stealing campaign
- The Hacker News: FBI warns FortiBleed remains active
- Lumen Black Lotus Labs: Canto incognito, tracking the PoeLLM malware
- BleepingComputer: Microsoft Teams to get support for third-party deepfake detection tools
- Microsoft 365 roadmap RM573451: third-party synthetic audio and video detection in Teams
Want a second pair of eyes on your edge devices? Please get in touch.
More like this
- Seven Korean lenders breached through side doors, with an AI tool suspected 5 october 2026
- A 16-year-old's ransomware gang ran on unlocked doors 2 october 2026
- ShinyHunters walks round the PeopleSoft firewall fix with one character 28 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.