Skip to main content
FortinetSecurity incident

Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks

What happened

Fortinet's FortiGate firewalls are targeted in a large-scale credential-harvesting campaign called "Fortibleed," compromising credentials for up to 75,000 devices and providing ransomware operators with access to corporate networks.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

A coordinated wave of exploitation targeting edge VPN and firewall appliances from four major vendors Palo Alto Networks, Fortinet, Citrix, and Check Point has emerged as the dominant initial-access vector for ransomware operators in mid-2026. Threat actors, including affiliates of the Qilin ransomware-as-a-service (RaaS) operation, are chaining authentication-bypass flaws, credential-harvesting campaigns, and legacy-protocol weaknesses to obtain unauthenticated or credential-free access to corporate perimeters. Once inside, these actors move rapidly toward lateral movement, data exfiltration, and double-extortion ransomware deployment, often within days of a CVE's public disclosure. The campaigns analyzed here span four separate but converging incidents: the "Fortibleed" mass credential-compromise campaign against roughly 75,000 internet-facing FortiGate firewalls; active exploitation of the Palo Alto GlobalProtect authentication-bypass flaw CVE-2026-0257 ; Qilin-linked exploitation of the Check Point VPN authentication-bypass flaw CVE-2026-50751 tied to the deprecated IKEv1 protocol; and rapid in-the-wild abuse of a new CitrixBleed-style NetScaler memory-disclosure bug, CVE-2026-8451 . Each incident underscores the same operational reality: internet-facing remote access infrastructure has become the ransomware ecosystem's preferred front door. Enterprise VPN and firewall...

Keep reading with a free account

The rest of this article, and every signal for Fortinet, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Product
FortiGate
Issue
“Fortibleed” mass credential-compromise campaign

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
“Fortibleed” mass credential-compromise campaign

Topics and mentions

Product tags

  • security
  • general technology

Extraction

Confidence
90%
Detected
Jul 27, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Fortinet and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Fortinet this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/93a01885-67db-3986-699c-10c154871cb8 returns this record as JSON. POST /v1/companies/enrich returns every signal for fortinet.com.

{
  "signal_id": "93a01885-67db-3986-699c-10c154871cb8",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-07-27T08:12:16+00:00",
  "company": {
    "name": "Fortinet",
    "domain": "fortinet.com"
  },
  "data": {
    "url": "https://cybersecuritynews.com/ransomware-gangs-attack-vpn/",
    "title": "Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks - CyberSecurityNews",
    "excerpt": "A coordinated wave of exploitation targeting edge VPN and firewall appliances from four major vendors Palo Alto Networks, Fortinet, Citrix, and Check Point has emerged as the dominant initial-access vector for ransomware operators in mid-2026. Threat actors, including affiliates of the Qilin ransomware-as-a-service (RaaS) operation , are chaining authentication-bypass flaws, credential-harvesting campaigns, and legacy-protocol weaknesses to obtain unauthenticated or credential-free access to corporate perimeters. Once inside, these actors move rapidly toward lateral movement, data exfiltration, and double-extortion ransomware deployment, often within days of a CVE’s public disclosure. The campaigns analyzed here span four separate but converging incidents: the “Fortibleed” mass credential-compromise campaign against roughly 75,000 internet-facing FortiGate firewalls; active exploitation of the Palo Alto GlobalProtect authentication-bypass flaw CVE-2026-0257 ; Qilin-linked exploitation of the Check Point VPN authentication-bypass flaw CVE-2026-50751 tied to the deprecated IKEv1 protocol; and rapid in-the-wild abuse of a new CitrixBleed-style NetScaler memory-disclosure bug, CVE-2026-8451 . Each incident underscores the same operational reality: internet-facing remote access infrastructure has become the ransomware ecosystem’s preferred front door. Enterprise VPN and firewall...",
    "product": "FortiGate",
    "summary": "Fortinet's FortiGate firewalls are targeted in a large-scale credential-harvesting campaign called \"Fortibleed,\" compromising credentials for up to 75,000 devices and providing ransomware operators with access to corporate networks.",
    "planning": false,
    "image_url": "http://cybersecuritynews.com/wp-content/uploads/2026/07/Ransomware-Gangs-Attack-VPN1.webp",
    "confidence": 0.9,
    "product_data": {
      "name": "FortiGate",
      "full_text": "FortiGate firewalls",
      "fuzzy_match": false
    },
    "product_tags": [
      "security",
      "general_technology"
    ],
    "published_at": "2026-07-27T08:12:16Z",
    "vulnerability": "“Fortibleed” mass credential-compromise campaign",
    "article_sentence": "The campaigns analyzed here span four separate but converging incidents: the “Fortibleed” mass credential-compromise campaign against roughly 75,000 internet-facing FortiGate firewalls; active exploitation of the Palo Alto GlobalProtect authentication-bypass flaw CVE-2026-0257 ; Qilin-linked exploitation of the Check Point VPN authentication-bypass flaw CVE-2026-50751 tied to the deprecated IKEv1 protocol; and rapid in-the-wild abuse of a new CitrixBleed-style NetScaler memory-disclosure bug, CVE-2026-8451 ."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.