decrypted · 13 july 2026 · ransomware and cybercrime · vulnerabilities and patching
No zero-day needed: the FortiBleed credentials now for sale
Login credentials for the Foreign Office, several NHS trusts, energy suppliers and at least two local councils are being offered for sale on dark web forums this week, for as much as $60,000 (£44,000). They come from FortiBleed, a months-old campaign against internet-facing Fortinet firewalls and VPN gateways that the NCSC first warned about on 18 June. What has changed since then isn't the attack, it's the aftermath: the harvested logins are now a commercial product, and buyers are reportedly window-shopping for follow-on ransomware access. The uncomfortable detail, confirmed by Fortinet itself, is that none of this required a new vulnerability at all.
No zero-day required
FortiBleed's name suggests a software flaw, echoing Heartbleed, but Fortinet has been clear that the campaign is built on brute-force, dictionary and credential-stuffing attempts against devices with weak or reused passwords and no multi-factor authentication. A Russian-speaking criminal group appears to have combined credentials leaked in older, unrelated breaches with automated guessing against internet-facing FortiGate devices, verifying a database of 86,644 working credentials drawn from more than 74,000 devices across 194 countries. The NCSC's advisory put the method plainly: attackers use passwords stolen from one service to try their luck on another. It's the digital equivalent of a lost bunch of house keys turning up at a locksmith who quietly tries each one on every door in the street. No lock was picked. Enough doors just used the same key.
The Secure by Design lesson
The organisations named this week did not fail to patch anything; they failed to make reuse and single-factor logins impossible in the first place. That is precisely the gap Secure by Design is meant to close: security that depends on every administrator choosing a strong, unique password and remembering to enable MFA will eventually fail, because someone won't. The NCSC's own remediation advice this week amounts to a design checklist, not a patching one: enforce MFA on every VPN and management login, remove management interfaces from the internet where they don't need to be there, and treat any password that has ever been reused elsewhere as already compromised. UK boards reviewing supplier and internal access this month should ask a sharper question than "are we patched": can our administrative interfaces be reached from the open internet at all, and would a stolen password from an unrelated breach actually get an attacker anywhere on our network. If the answer to the second question is yes, that's a design decision waiting to be made, not a training reminder waiting to be repeated.
Also this week
An AI agent platform joins the actively exploited list. CISA gave US federal agencies until 11 July to patch CVE-2026-55255, a critical authorisation bypass in Langflow, the open-source tool for building AI agent workflows. The flaw lets an authenticated user execute another user's flows simply by supplying their identifier, no ownership check required. Sysdig first spotted exploitation on 25 June, with attackers using it to deploy loaders and harvest cloud and LLM credentials. It's a reminder that access-control basics don't get a pass just because the product in front of them is labelled AI.
Fake payment SDKs hit npm and PyPI. Researchers at Socket found 17 malicious packages published within minutes of each other on 7 July, impersonating SDKs for Paysafe, Skrill and Neteller. Rather than talking to the real payment APIs, the fakes returned convincing success responses while quietly harvesting API keys, AWS credentials and GitHub and npm tokens from developer environments. Socket's scanners caught the cluster within six minutes, which is the only reason this is a footnote rather than a headline: UK teams pulling third-party packages by name alone, without provenance checks, remain exposed to exactly this trick.
Ofcom's age-assurance clock is ticking. Providers served with Online Safety Act legal notices must submit updated risk assessment records in the window between 1 May and 31 July, and Ofcom is due to publish its first statutory report on how well age-verification technology actually works this month. Age checks solve one problem while creating another: the identity and biometric data collected to prove someone is over 18 has to live somewhere, and "highly effective" verification is only a win for users if that data is held with the same rigour as the harm it was meant to prevent.
Sources
- NCSC: Advice following global targeting of Fortinet firewalls and VPN gateways
- IT Pro: The FortiBleed campaign just took a turn for the worse
- Insurance Business: Russian hackers expose UK government logins in FortiBleed credential breach
- BleepingComputer: CISA orders feds to prioritize patching Langflow auth bypass flaw
- Socket: Coordinated npm and PyPI campaign typosquats popular secure payment apps
- Global Dating Insights: Ofcom steps up online safety oversight, publishes new deadlines
If FortiBleed has you rethinking who can reach your admin logins from the internet, get in touch.
More like this
- The npm maintainer account North Korea phished, and the four packages it unlocked 31 july 2026
- The Department for Education's helpdesk, and the 607,000 records it was never built to hold 31 july 2026
- An SD-WAN console with no way to hide, and the flaw attackers found first 28 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.