Bg Shape
Image

FortiBleed just got worse, 78 Microsoft accounts hit, and a 9.6 vulnerability in Kemp LoadMaster

Robert Kehoe
Chief Technology Officer
Published:
July 20, 2026

1. FortiBleed: 110 Million Credentials Harvested Across 430,000 FortiGate Firewalls

What happened

FortiBleed has compromised more than 430,000 FortiGate firewalls globally since at least February 2026, siphoning over 110 million credentials directly from live network traffic. SOCRadar has confirmed that the INC and Lynx ransomware groups are responsible, with 354 intrusions documented and at least 12 confirmed ransomware deployments to date.

The attackers weaponised FortiOS's own native diagnostic command to passively intercept authentication traffic, including RADIUS, NTLM, and Kerberos credentials, without triggering standard perimeter alarms.

What to do

  • Rotate any credentials that have touched FortiGate devices since June 2026
  • Audit admin accounts for unrecognised sessions or logins from external IP addresses
  • Check for an unauthorised backdoor admin account named "adminin"

2. Microsoft 365 Password Spray: 81 Million Attempts, MFA Bypassed

What happened

Between June 12 and June 26, 2026, attackers generated more than 81 million login attempts against Microsoft 365 and Azure CLI, compromising 78 accounts across 64 organisations. Fifteen of the 23 organisations hit on the campaign's peak day had MFA enabled. It made no difference.

The attack exploited the OAuth ROPC flow, a deprecated legacy authentication method still supported by Azure CLI. Because ROPC bypasses the authorisation endpoint entirely, Conditional Access Policies that enforce MFA at that endpoint never fired.

What to do

  • Block legacy authentication protocols tenant-wide
  • Ensure Conditional Access policies cover all users, all cloud apps, and all client app types unconditionally
  • Audit sign-in logs for ROPC-based token grants

3. Kemp LoadMaster: Pre-Auth Root Command Execution Under Active Attack

What happened

CVE-2026-8037 (CVSS 9.6) is an OS command injection vulnerability in Progress Kemp LoadMaster. An unauthenticated attacker with network access to the LoadMaster API can execute arbitrary commands as root with a single crafted request. Active exploitation began June 29, 2026, the same day a public proof-of-concept was published.

What to do

  • Install the latest LoadMaster firmware immediately
  • Treat any LoadMaster with API credentials as compromised until logs have been reviewed
  • Restrict LoadMaster API access to trusted internal IP ranges

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Read Our Latest Blogs

Blog Image
Three Things Security Leaders Must Know About NIS 2

Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.

Blog Image
Miasma Worm, Microsoft Mega Patch Tuesday & Defender Bypass

This week's Risk Radar covers the Miasma supply chain worm hitting 73 Microsoft GitHub repositories, the largest Patch Tuesday in Microsoft's history including a critical Secure Boot deadline, and a confirmed Microsoft Defender bypass that lets attackers elevate to SYSTEM privileges.

Blog Image
Why your NIS2 Gap Might Sit Outside IT

Discover why NIS2 readiness needs to move beyond policy documents and into operational response planning across IT, OT, and supplier ecosystems.

Bg ShapeBg Shape
BLOGS & INSIGHTS

FortiBleed just got worse, 78 Microsoft accounts hit, and a 9.6 vulnerability in Kemp LoadMaster

Ransomware and Malware
Identity and Access
Vulnerabilities and Exposure
Robert Kehoe
Chief Technology Officer
July 3, 2026

1. FortiBleed: 110 Million Credentials Harvested Across 430,000 FortiGate Firewalls

What happened

FortiBleed has compromised more than 430,000 FortiGate firewalls globally since at least February 2026, siphoning over 110 million credentials directly from live network traffic. SOCRadar has confirmed that the INC and Lynx ransomware groups are responsible, with 354 intrusions documented and at least 12 confirmed ransomware deployments to date.

The attackers weaponised FortiOS's own native diagnostic command to passively intercept authentication traffic, including RADIUS, NTLM, and Kerberos credentials, without triggering standard perimeter alarms.

What to do

  • Rotate any credentials that have touched FortiGate devices since June 2026
  • Audit admin accounts for unrecognised sessions or logins from external IP addresses
  • Check for an unauthorised backdoor admin account named "adminin"

2. Microsoft 365 Password Spray: 81 Million Attempts, MFA Bypassed

What happened

Between June 12 and June 26, 2026, attackers generated more than 81 million login attempts against Microsoft 365 and Azure CLI, compromising 78 accounts across 64 organisations. Fifteen of the 23 organisations hit on the campaign's peak day had MFA enabled. It made no difference.

The attack exploited the OAuth ROPC flow, a deprecated legacy authentication method still supported by Azure CLI. Because ROPC bypasses the authorisation endpoint entirely, Conditional Access Policies that enforce MFA at that endpoint never fired.

What to do

  • Block legacy authentication protocols tenant-wide
  • Ensure Conditional Access policies cover all users, all cloud apps, and all client app types unconditionally
  • Audit sign-in logs for ROPC-based token grants

3. Kemp LoadMaster: Pre-Auth Root Command Execution Under Active Attack

What happened

CVE-2026-8037 (CVSS 9.6) is an OS command injection vulnerability in Progress Kemp LoadMaster. An unauthenticated attacker with network access to the LoadMaster API can execute arbitrary commands as root with a single crafted request. Active exploitation began June 29, 2026, the same day a public proof-of-concept was published.

What to do

  • Install the latest LoadMaster firmware immediately
  • Treat any LoadMaster with API credentials as compromised until logs have been reviewed
  • Restrict LoadMaster API access to trusted internal IP ranges

Stay safe and share this with your team.

Smarttech247 is a Gartner-recognised MDR provider. If any of these vulnerabilities affect your environment and you need support, get in touch.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365