Credential attacks surge: FortiBleed and password spraying
Large-scale credential attack campaigns. FortiBleed targets Fortinet, Sophos, MSSQL devices via multi-stage password spraying and config extraction; IAB on Exploit[.]in claims responsibility. Password spraying attacks surge 155x, with one campaign hitting 81M attempts in two weeks, exploiting legacy auth and MFA gaps. Aligns with ongoing edge device targeting trends. Actionable mitigation steps provided.
Sources (2)
Updated Aug 19, 2026