Bg Shape
Image

FortiBleed just got worse, 78 Microsoft accounts hit, and a 9.6 vulnerability in Kemp LoadMaster

Robert Kehoe
Chief Technology Officer
Published:
July 20, 2026

1. FortiBleed: 110 Million Credentials Harvested Across 430,000 FortiGate Firewalls

What happened

FortiBleed has compromised more than 430,000 FortiGate firewalls globally since at least February 2026, siphoning over 110 million credentials directly from live network traffic. SOCRadar has confirmed that the INC and Lynx ransomware groups are responsible, with 354 intrusions documented and at least 12 confirmed ransomware deployments to date.

The attackers weaponised FortiOS's own native diagnostic command to passively intercept authentication traffic, including RADIUS, NTLM, and Kerberos credentials, without triggering standard perimeter alarms.

What to do

  • Rotate any credentials that have touched FortiGate devices since June 2026
  • Audit admin accounts for unrecognised sessions or logins from external IP addresses
  • Check for an unauthorised backdoor admin account named "adminin"

2. Microsoft 365 Password Spray: 81 Million Attempts, MFA Bypassed

What happened

Between June 12 and June 26, 2026, attackers generated more than 81 million login attempts against Microsoft 365 and Azure CLI, compromising 78 accounts across 64 organisations. Fifteen of the 23 organisations hit on the campaign's peak day had MFA enabled. It made no difference.

The attack exploited the OAuth ROPC flow, a deprecated legacy authentication method still supported by Azure CLI. Because ROPC bypasses the authorisation endpoint entirely, Conditional Access Policies that enforce MFA at that endpoint never fired.

What to do

  • Block legacy authentication protocols tenant-wide
  • Ensure Conditional Access policies cover all users, all cloud apps, and all client app types unconditionally
  • Audit sign-in logs for ROPC-based token grants

3. Kemp LoadMaster: Pre-Auth Root Command Execution Under Active Attack

What happened

CVE-2026-8037 (CVSS 9.6) is an OS command injection vulnerability in Progress Kemp LoadMaster. An unauthenticated attacker with network access to the LoadMaster API can execute arbitrary commands as root with a single crafted request. Active exploitation began June 29, 2026, the same day a public proof-of-concept was published.

What to do

  • Install the latest LoadMaster firmware immediately
  • Treat any LoadMaster with API credentials as compromised until logs have been reviewed
  • Restrict LoadMaster API access to trusted internal IP ranges

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Read Our Latest Blogs

Blog Image
JFrog Confirmed AI Attack, Minnesota Water Attack & Coca-Cola Refuse to Pay

JFrog patches the zero-day used in the Hugging Face breach, Coca-Cola's Fairlife hit by Anubis ransomware, and a coordinated attack knocks out Minnesota water systems.

Blog Image
Ghost Executive: The Fast-Growing Fraud Impersonating Your Leadership

A Ghost Executive attack is a form of business email compromise (BEC) in which a fraudster impersonates a senior figure to authorise a fraudulent payment or reroute a legitimate one. Read more at Smarttech247

Blog Image
Autonomous AI Attacks, Ransomware Disruption, and a Critical WordPress Threat

Explore this week's Risk Radar covering autonomous AI cyberattacks, the Anubis ransomware attack, and a critical WordPress vulnerability, with key guidance for CISOs.

Bg ShapeBg Shape
BLOGS & INSIGHTS

FortiBleed just got worse, 78 Microsoft accounts hit, and a 9.6 vulnerability in Kemp LoadMaster

Ransomware and Malware
Identity and Access
Vulnerabilities and Exposure
Robert Kehoe
Chief Technology Officer
July 3, 2026

1. FortiBleed: 110 Million Credentials Harvested Across 430,000 FortiGate Firewalls

What happened

FortiBleed has compromised more than 430,000 FortiGate firewalls globally since at least February 2026, siphoning over 110 million credentials directly from live network traffic. SOCRadar has confirmed that the INC and Lynx ransomware groups are responsible, with 354 intrusions documented and at least 12 confirmed ransomware deployments to date.

The attackers weaponised FortiOS's own native diagnostic command to passively intercept authentication traffic, including RADIUS, NTLM, and Kerberos credentials, without triggering standard perimeter alarms.

What to do

  • Rotate any credentials that have touched FortiGate devices since June 2026
  • Audit admin accounts for unrecognised sessions or logins from external IP addresses
  • Check for an unauthorised backdoor admin account named "adminin"

2. Microsoft 365 Password Spray: 81 Million Attempts, MFA Bypassed

What happened

Between June 12 and June 26, 2026, attackers generated more than 81 million login attempts against Microsoft 365 and Azure CLI, compromising 78 accounts across 64 organisations. Fifteen of the 23 organisations hit on the campaign's peak day had MFA enabled. It made no difference.

The attack exploited the OAuth ROPC flow, a deprecated legacy authentication method still supported by Azure CLI. Because ROPC bypasses the authorisation endpoint entirely, Conditional Access Policies that enforce MFA at that endpoint never fired.

What to do

  • Block legacy authentication protocols tenant-wide
  • Ensure Conditional Access policies cover all users, all cloud apps, and all client app types unconditionally
  • Audit sign-in logs for ROPC-based token grants

3. Kemp LoadMaster: Pre-Auth Root Command Execution Under Active Attack

What happened

CVE-2026-8037 (CVSS 9.6) is an OS command injection vulnerability in Progress Kemp LoadMaster. An unauthenticated attacker with network access to the LoadMaster API can execute arbitrary commands as root with a single crafted request. Active exploitation began June 29, 2026, the same day a public proof-of-concept was published.

What to do

  • Install the latest LoadMaster firmware immediately
  • Treat any LoadMaster with API credentials as compromised until logs have been reviewed
  • Restrict LoadMaster API access to trusted internal IP ranges

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365