- [2026.06.24]FortiBleed from the Target Side: What Stops Them [Part 3/3]
Half the FortiBleed sprayer IPs — including several that successfully validated the admin account — carry a threat score of zero and appear on no abuse feed at all. The only rule that catches 100% of them is a management-interface allowlist. This is Part 3 of three: the defenses that work, why standard SOC rules miss this spray, the ASN-level indicators, and the timeline gap that is the real lesson. With a companion Detection Brief.
- [2026.06.24]FortiBleed Credential-Validation Spray: Detection Brief
SOC-ready companion to FortiBleed from the Target Side. The highest-signal detections for the credential-validation phase: off-allowlist admin auth, one source testing many usernames at a steady 24/7 cadence, a single success after a run of failures, and FortiGate service/cloud accounts appearing at the login prompt. TLP:CLEAR.