- [2026.06.24]FortiBleed from the Target Side: The Corpus [Part 1/3]
We ran an internet-facing FortiGate honeypot for a month. It logged about 447,600 login attempts from about 34,600 IP addresses, and for three days we captured every submitted credential in cleartext. The corpus is not brute force: it is a stolen corpus of real corporate credentials being recycled, complete with FortiGate service accounts that exist only inside a device configuration backup. This is Part 1 of three: what FortiBleed actually is, and what the spray looks like from inside the device it targets.
- [2026.06.24]FortiBleed from the Target Side: The Ecosystem [Part 2/3]
The same stolen FortiBleed corpus is sprayed at one honeypot, in parallel, by roughly a dozen operator clusters across about 13 autonomous systems — and a synthetic heartbeat fired by twelve machines on three 'different' networks within the same minute proves part of that crowd is one operator wearing several masks. This is Part 2 of three: the marketplace, the orchestrated fleet, the victims named by their own stolen passwords, and the validate-and-leave fingerprint of an Initial Access Broker.