Key Takeaways
- CISA advises organizations to terminate VPN sessions and rotate credentials following the FortiBleed exposure.
- CloudSEK identified roughly 148 confirmed Active Directory compromises despite tens of thousands of exposed FortiGate devices.
- Analysts note accelerating movement toward zero trust as enterprises reconsider dependence on traditional VPN appliances.
CISA’s warnings regarding the FortiBleed campaign, tied to analysis published on June 19, 2026, detail how attackers used exposed Fortinet FortiGate appliances to harvest credentials at scale. The campaign affected roughly 74,000 to 80,000 devices across more than 190 countries. Despite this expansive initial exposure, investigators concluded that only a smaller subset progressed to full domain compromise.
CISA recommends that impacted organizations terminate active VPN sessions, rotate all high-value credentials, enforce phishing-resistant MFA, and restrict public access to device management interfaces. These steps break authentication artifacts that attackers captured during earlier phases of the campaign.
Mass exploitation of VPN and remote access devices has steadily increased. ENISA reports that compromises of remote access systems constitute more than 20% of initial access techniques in major incidents. Campaigns like FortiBleed target infrastructure used to route authenticated traffic. Remote access appliances become a single point where attackers can steal credentials, pivot toward Active Directory, and establish persistent control.
The analysis from CloudSEK, highlighted in an update from DoublePulsar, details the post-exploitation phase. Out of the tens of thousands of exposed devices, investigators identified roughly 148 organizations with confirmed Active Directory compromise. This fraction marks a critical escalation, as domain-level control typically precedes ransomware deployment or data theft. The data also helps explain why certain login patterns repeat across victims: older backdoors from earlier ransomware groups were left in place, allowing overlapping criminal operators to reuse harvested credentials.
The DoublePulsar analysis also indicates that multiple actors may be piggybacking on the same pool of exposed devices. This complicates attribution when different groups leverage identical misconfigurations. For security teams responding to an event, determining whether the blast radius reached identity infrastructure takes precedence over attributing the attack to a specific actor.
Exposure levels vary across organizations. Those following hardened configuration guidance from NIST’s zero trust model in NIST SP 800-207 and the access controls outlined in NIST 800-53 often limit the impact of perimeter device failures by making network access conditional and segmented. However, within many enterprises, traditional VPN appliances remain deeply embedded in daily workflows.
Gartner projects that by 2027, 50% of organizations will adopt some form of zero trust network access (ZTNA) over VPNs. The repeated exploitation of Fortinet FortiGate, Citrix, and Check Point devices is accelerating this shift. These incidents demonstrate how attackers target widely deployed products with long upgrade cycles. VPN and firewall platforms fit that pattern, as replacing them requires capital expenditure and planned downtime.
Massive perimeter exposure does not always translate into massive network compromise because attackers prioritize environments that offer immediate paths to domain privileges. CloudSEK’s observation that only a subset of exposed organizations showed signs of Active Directory takeover aligns with this operational model. Consequently, CISA’s guidance emphasizes credential resets and MFA enforcement to invalidate the stolen tokens and passwords attackers rely on for lateral movement.
Organizations are using the FortiBleed event to audit perimeter device inventories and decommission unpatched or forgotten VPN portals. Reviewing identity logs from the period of exposure helps identify anomalies, while external incident response firms are often retained to validate whether downstream systems show signs of lateral movement.
The latest FortiBleed analysis underscores both the vast scale of the exposed attack surface and the specific targeting required to achieve deep network compromise. Because remote access infrastructure remains a primary target for threat actors, these large-scale exploitation events act as a direct catalyst for organizations to accelerate their adoption of zero trust architectures.
⬇️