Decrypted: The UK Cyber Briefing
Oct 8, 2026 · 5 min · 6 segments
The FBI and US Secret Service say the FortiBleed campaign against Fortinet firewalls is still active, with administrators locked out and access passed to ransomware affiliates. No vulnerability is…
The FBI and US Secret Service warned this week that FortiBleed is still running, and it's now locking administrators out of their own devices.
What's new is the joint advisory of Tuesday, the 6th of October.
The stolen access is being passed to ransomware affiliates, and the uncomfortable part, nobody needs a vulnerability for any of this.
Next, a front door with a guessable key.
Think of a firewall as the reinforced front door of your network.
FortiBleed doesn't break the door.
It tries keys that have already leaked, passwords reused from earlier breaches or lifted from info stealer malware on staff laptops.
Attackers spray those at internet-facing VPN portals.
Once one works, they pull out the device's stored password hashes.
A hash is a scrambled fingerprint of a password.
The agencies say Fortinet's legacy SHA-256 storage lets those fingerprints be cracked offline on a bank of graphics cards where no alarm can ring.
The operators then create their own administrator accounts.
Sometimes they delete the real ones or change their passwords, so the owner can't get back in.
The advisory also says that recovering from this takes more than patching and a password reset, and also, what the numbers do and don't say.
The FBI and US Secret Service warned this week that FortiBleed is still running, and it's now locking administrators out of their own devices.
What's new is the joint advisory of Tuesday, the 6th of October.
The stolen access is being passed to ransomware affiliates, and the uncomfortable part, nobody needs a vulnerability for any of this.
Next, a front door with a guessable key.
Think of a firewall as the reinforced front door of your network.
FortiBleed doesn't break the door.
It tries keys that have already leaked, passwords reused from earlier breaches or lifted from info stealer malware on staff laptops.
Attackers spray those at internet-facing VPN portals.
Once one works, they pull out the device's stored password hashes.
A hash is a scrambled fingerprint of a password.
The agencies say Fortinet's legacy SHA-256 storage lets those fingerprints be cracked offline on a bank of graphics cards where no alarm can ring.
The operators then create their own administrator accounts.
Sometimes they delete the real ones or change their passwords, so the owner can't get back in.
The advisory also says that recovering from this takes more than patching and a password reset, and also, what the numbers do and don't say.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.