- [2026.06.24]FortiBleed from the Target Side: The Corpus [Part 1/3]
We ran an internet-facing FortiGate honeypot for a month. It logged about 447,600 login attempts from about 34,600 IP addresses, and for three days we captured every submitted credential in cleartext. The corpus is not brute force: it is a stolen corpus of real corporate credentials being recycled, complete with FortiGate service accounts that exist only inside a device configuration backup. This is Part 1 of three: what FortiBleed actually is, and what the spray looks like from inside the device it targets.
- [2026.06.24]FortiBleed from the Target Side: The Ecosystem [Part 2/3]
The same stolen FortiBleed corpus is sprayed at one honeypot, in parallel, by roughly a dozen operator clusters across about 13 autonomous systems — and a synthetic heartbeat fired by twelve machines on three 'different' networks within the same minute proves part of that crowd is one operator wearing several masks. This is Part 2 of three: the marketplace, the orchestrated fleet, the victims named by their own stolen passwords, and the validate-and-leave fingerprint of an Initial Access Broker.
- [2026.06.24]FortiBleed from the Target Side: What Stops Them [Part 3/3]
Half the FortiBleed sprayer IPs — including several that successfully validated the admin account — carry a threat score of zero and appear on no abuse feed at all. The only rule that catches 100% of them is a management-interface allowlist. This is Part 3 of three: the defenses that work, why standard SOC rules miss this spray, the ASN-level indicators, and the timeline gap that is the real lesson. With a companion Detection Brief.