Key Takeaways
- Fortinet found no new vulnerability behind the FortiBleed credential exposure, leaving customers without a single software patch that resolves the risk.
- Valid VPN credentials can make initial access look routine, shifting attention toward MFA, session risk and post-login activity.
- Execution-prevention layers, such as Automated Moving Target Defense, complement identity and endpoint controls to disrupt payloads from authenticated attackers.
Fortinet’s investigation into the FortiBleed leak points to an uncomfortable conclusion for enterprise security teams: the exposed credentials were reportedly compiled through earlier incidents and brute-force activity, not obtained by exploiting a newly discovered FortiGate vulnerability. The immediate problem, then, is not a missing security update. It is that functioning usernames and passwords may already be in criminal hands.
Researchers found an exposed server containing usernames, email addresses and passwords associated with 73,000 to 75,000 Fortinet FortiGate firewalls across 194 countries. The June 2026 campaign affected roughly 50% of the internet-exposed Fortinet firewall population identified at the time, according to the Cloud Security Alliance. Broader reporting on the operation said its tooling harvested more than 110 million credentials from over 430,000 FortiGate devices, including RADIUS, NTLM, Kerberos and database passwords captured in transit. Those figures represent different slices of the campaign rather than interchangeable totals.
Authentication systems are designed to accept valid credentials. If an attacker enters the correct password, the initial session can resemble an employee connecting remotely. There may be no exploit signature, malicious attachment or failed authentication sequence for conventional monitoring tools to flag. Context can still expose risk, including an unusual location, device, access time or sequence of actions, but a successful login alone offers limited evidence about who is operating the account.
That limitation does not make detection irrelevant. It changes what defenders need to observe. The Cyber Security Agency of Singapore advised organizations to address compromised FortiGate credentials, reflecting the need for password resets, account reviews and stronger authentication rather than a patch-only response. Fortinet customers should also examine administrator accounts, SSL VPN access, authentication logs and downstream systems for evidence that exposed credentials were replayed.
What happens after the login? Attackers can enumerate internal resources, seek privileged accounts, move toward Active Directory and prepare ransomware deployment. Those activities can produce signals for identity threat detection and response, EDR, XDR and network monitoring even when the opening authentication appeared ordinary. Fortinet, CrowdStrike and Okta have accordingly placed greater emphasis on MFA, conditional access and identity-focused detection. The objective is to evaluate the session throughout its life, not grant lasting trust because one password was accepted.
This approach tracks with NIST SP 800-207 Zero Trust Architecture, which recommends removing implicit trust based on network location and repeatedly evaluating access requests. In practice, enterprises can reduce exposure by adopting phishing-resistant MFA where feasible, restricting administrative interfaces, applying least privilege, shortening session duration and requiring fresh authentication for sensitive actions. Credential rotation still matters. So does checking whether the same password was reused across VPN, directory, cloud and database accounts.
Morphisec adds another layer to that model through Automated Moving Target Defense, or AMTD. The technology changes aspects of the runtime memory environment to interfere with malicious code as it attempts to execute. Its value proposition is that it does not need to determine whether the person behind a VPN session is the account owner. Instead, it focuses on disrupting a later payload before encryption or other damaging execution proceeds.
That said, execution prevention is not a universal substitute for identity controls. Some intrusions abuse legitimate administration tools, steal data without deploying ransomware or manipulate cloud services through authorized interfaces. Morphisec AMTD can augment NGAV, EDR and XDR against relevant payload techniques, while MFA, conditional access, segmentation and behavioral monitoring address other stages of an intrusion.
FortiBleed therefore gives security leaders a broader planning lesson. Patch management remains important, but vulnerability remediation covers only one route into an enterprise. When attackers arrive with authentic credentials, organizations need overlapping controls across identity, session monitoring, privilege management and endpoint execution. The front door may recognize the password. The rest of the environment still has opportunities to limit what that session can do.
⬇️