Researchers and national defenders warned that FortiBleed has left more than 75,000 Fortinet firewall devices compromised, exposing organizations worldwide through internet-facing security infrastructure. Hudson Rock first reported tens of thousands of affected Fortinet systems and later raised the estimate above 75,000, describing broad exposure across global enterprises and highlighting the scale of the compromise.
CERT Bulgaria subsequently issued a public warning on FortiBleed, reinforcing that the incident affects a massive number of Fortinet firewall devices and poses a serious risk to exposed organizations. The combined reporting indicates a widespread compromise of perimeter security appliances, with impacted enterprises facing potential unauthorized access, data exposure, and downstream intrusion risk through trusted network defenses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The UK National Cyber Security Centre issued guidance for organizations affected by the FortiBleed credential theft campaign, warning that some victims may already have suffered full network compromise. It advised customers to check exposure, isolate affected devices, reset and investigate them, and harden rebuilt systems with updates, MFA, unique passwords, and PBKDF2.
CERT Bulgaria published a warning about FortiBleed, citing more than 75,000 compromised Fortinet firewall devices after the attack. The notice reflects official government CERT amplification of the reported incident.
A later Hudson Rock report said the number of compromised Fortinet firewalls had risen to 75,000 and described global enterprises as exposed. This represents an escalation in the reported scale of the incident.
Hudson Rock published a FortiBleed report stating that more than 73,932 Fortinet firewall devices had been compromised. The report framed the issue as exposing organizations through infected firewall appliances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcegovcert.bg
Open sourcehudsonrock.com
Open sourcehudsonrock.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.