TI Mindmap HUB
Threat Intelligence Report

More Than a Leak: What SpyCloud Found Inside the FortiBleed Threat Actor Infrastructure

📅 June 20, 2026 📰 spycloud.com 🔍 0 CVE(s) referenced

SpyCloud’s investigation reveals that the FortiBleed threat actor operated a sophisticated, AI-enhanced, multi-server infrastructure to indiscriminately brute-force and monetize access to tens of thousands of internet-facing devices—including Fortinet firewalls, Synology NAS, Sophos firewalls, and MSSQL servers—culminating in the exfiltration of sensitive military data and the sale of network access on underground forums.

unclassified

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle