
The FortiBleed campaign keeps getting bigger. SOCRadar’s latest research ties the operation which targeted more than 430,000 FortiGate firewalls and planted custom traffic sniffers on roughly 19,000 devices to intercept VPN credentials directly to the INC and Lynx ransomware operations, with evidence of a ~20-member crew, 500+ operational servers, and persistent “admin” backdoor accounts. For defenders, this is a scoping problem disguised as a patching problem. If your edge devices were exposed, the questions that matter are investigative:
which credentials transited that device during the compromise window,
which of those accounts authenticated somewhere new afterward
do any of your VPN sessions since then originate from suspect infrastructure?
Those answers live across firewall configs, IdP logs, and VPN telemetry which is exactly the cross-system investigation that quietly consumes senior analyst weeks.
