As cited
Copy frozen at (site build).
ransomware
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
Security researchers have linked the FortiBleed credential theft campaign to infrastructure associated with both INC and Lynx ransomware operations, with evidence showing operators managing negotiation panels for both groups. The stolen FortiGate credentials appear to be harvested for follow-on ransomware deployment rather than standalone credential trafficking.
Why it matters: Organizations running FortiGate devices should prioritize patching and monitoring for signs of credential compromise, as stolen credentials are being actively used to facilitate ransomware attacks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
Security researchers have linked the FortiBleed credential theft campaign to infrastructure associated with both INC and Lynx ransomware operations, with evidence showing operators managing negotiation panels for both groups. The stolen FortiGate credentials appear to be harvested for follow-on ransomware deployment rather than standalone credential trafficking.
Why it matters: Organizations running FortiGate devices should prioritize patching and monitoring for signs of credential compromise, as stolen credentials are being actively used to facilitate ransomware attacks.
- Source published
- First seen by Cybersecurity Tracker