Bg Shape
Image

FortiBleed just got worse, 78 Microsoft accounts hit, and a 9.6 vulnerability in Kemp LoadMaster

Robert Kehoe
Chief Technology Officer
Published:
July 20, 2026

‍

1. FortiBleed: 110 Million Credentials Harvested Across 430,000 FortiGate Firewalls

What happened

FortiBleed has compromised more than 430,000 FortiGate firewalls globally since at least February 2026, siphoning over 110 million credentials directly from live network traffic. SOCRadar has confirmed that the INC and Lynx ransomware groups are responsible, with 354 intrusions documented and at least 12 confirmed ransomware deployments to date.

The attackers weaponised FortiOS's own native diagnostic command to passively intercept authentication traffic, including RADIUS, NTLM, and Kerberos credentials, without triggering standard perimeter alarms.

What to do

  • Rotate any credentials that have touched FortiGate devices since June 2026
  • Audit admin accounts for unrecognised sessions or logins from external IP addresses
  • Check for an unauthorised backdoor admin account named "adminin"

2. Microsoft 365 Password Spray: 81 Million Attempts, MFA Bypassed

What happened

Between June 12 and June 26, 2026, attackers generated more than 81 million login attempts against Microsoft 365 and Azure CLI, compromising 78 accounts across 64 organisations. Fifteen of the 23 organisations hit on the campaign's peak day had MFA enabled. It made no difference.

The attack exploited the OAuth ROPC flow, a deprecated legacy authentication method still supported by Azure CLI. Because ROPC bypasses the authorisation endpoint entirely, Conditional Access Policies that enforce MFA at that endpoint never fired.

What to do

  • Block legacy authentication protocols tenant-wide
  • Ensure Conditional Access policies cover all users, all cloud apps, and all client app types unconditionally
  • Audit sign-in logs for ROPC-based token grants

3. Kemp LoadMaster: Pre-Auth Root Command Execution Under Active Attack

What happened

CVE-2026-8037 (CVSS 9.6) is an OS command injection vulnerability in Progress Kemp LoadMaster. An unauthenticated attacker with network access to the LoadMaster API can execute arbitrary commands as root with a single crafted request. Active exploitation began June 29, 2026, the same day a public proof-of-concept was published.

What to do

  • Install the latest LoadMaster firmware immediately
  • Treat any LoadMaster with API credentials as compromised until logs have been reviewed
  • Restrict LoadMaster API access to trusted internal IP ranges

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Read Our Latest Blogs

Blog Image
Citrix NetScaler Mass Exploitation, Cisco's 9.8 CVE & Revolut Breached Again

Citrix NetScaler flaws face mass exploitation within a day of disclosure, Cisco's SD-WAN scores its eighth CVE of the year, and Revolut is breached again via a third-party supplier.

Blog Image
6 best MDR and XDR platforms for MSSPs in 2026

Compare six MDR and XDR platforms for MSSPs on multi-tenancy, compliance mapping and response speed, from CrowdStrike to Smarttech247 VisionX.

Blog Image
Microsoft Emergency Patch, Revolut Breach & Cisco's Second Perfect 10 CVSS

Microsoft rushes an emergency patch after last week's update broke Remote Desktop and hypervisor stability, Revolut discloses a process breach affecting 680+ high-net-worth clients, and Cisco scores another perfect 10 CVSS.

Bg ShapeBg Shape
BLOGS & INSIGHTS

FortiBleed just got worse, 78 Microsoft accounts hit, and a 9.6 vulnerability in Kemp LoadMaster

Ransomware and Malware
Identity and Access
Vulnerabilities and Exposure
Robert Kehoe
Chief Technology Officer
July 3, 2026

‍

1. FortiBleed: 110 Million Credentials Harvested Across 430,000 FortiGate Firewalls

What happened

FortiBleed has compromised more than 430,000 FortiGate firewalls globally since at least February 2026, siphoning over 110 million credentials directly from live network traffic. SOCRadar has confirmed that the INC and Lynx ransomware groups are responsible, with 354 intrusions documented and at least 12 confirmed ransomware deployments to date.

The attackers weaponised FortiOS's own native diagnostic command to passively intercept authentication traffic, including RADIUS, NTLM, and Kerberos credentials, without triggering standard perimeter alarms.

What to do

  • Rotate any credentials that have touched FortiGate devices since June 2026
  • Audit admin accounts for unrecognised sessions or logins from external IP addresses
  • Check for an unauthorised backdoor admin account named "adminin"

2. Microsoft 365 Password Spray: 81 Million Attempts, MFA Bypassed

What happened

Between June 12 and June 26, 2026, attackers generated more than 81 million login attempts against Microsoft 365 and Azure CLI, compromising 78 accounts across 64 organisations. Fifteen of the 23 organisations hit on the campaign's peak day had MFA enabled. It made no difference.

The attack exploited the OAuth ROPC flow, a deprecated legacy authentication method still supported by Azure CLI. Because ROPC bypasses the authorisation endpoint entirely, Conditional Access Policies that enforce MFA at that endpoint never fired.

What to do

  • Block legacy authentication protocols tenant-wide
  • Ensure Conditional Access policies cover all users, all cloud apps, and all client app types unconditionally
  • Audit sign-in logs for ROPC-based token grants

3. Kemp LoadMaster: Pre-Auth Root Command Execution Under Active Attack

What happened

CVE-2026-8037 (CVSS 9.6) is an OS command injection vulnerability in Progress Kemp LoadMaster. An unauthenticated attacker with network access to the LoadMaster API can execute arbitrary commands as root with a single crafted request. Active exploitation began June 29, 2026, the same day a public proof-of-concept was published.

What to do

  • Install the latest LoadMaster firmware immediately
  • Treat any LoadMaster with API credentials as compromised until logs have been reviewed
  • Restrict LoadMaster API access to trusted internal IP ranges

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365