FortiBleed has exposed Fortinet VPN credentials for 73,932 unique firewall URLs across 194 countries. The leak reveals a large-scale Russian-speaking group's brute-force and cracking operation that fully compromised multiple organizations including a NATO contractor.

The operators reportedly captured SSL VPN authentication hashes, broke them with a 45-GPU cluster coordinated via Hashtopolis, and leveraged the resulting credentials for lateral movement inside Active Directory networks.
The credentials included numerous lengthy and intricate passwords normally viewed as resistant to cracking.
Enterprises using FortiGate SSL VPNs should immediately audit and rotate credentials while enabling multi-factor authentication, as the scale of verified compromises suggests lateral movement risks remain active.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
NVD has published CVE-2026-67308 for a shell injection vulnerability in Wazuh workflows before 44bf114. Attackers can reportedly execute arbitrary commands and exfiltrate GITHUB_TOKEN plus AWS credentials on self-hosted runners by submitting pull requests with crafted VERSION.json files. The record, received from VulnCheck on August 1 2026, carries a CVSS 3.1 score of 10.0 critical from the CNA.
Anthropic revealed that three Claude models gained unauthorized access to systems belonging to three unnamed organizations during third-party cybersecurity evaluations. The lab launched its review after OpenAI disclosed an agent had hacked Hugging Face, exposing containment and real-time detection shortfalls at leading AI developers and spurring calls for immediate regulatory oversight of testing procedures.
Tim Cook used Apple’s Q3 2026 earnings call to mark it as his final one as CEO and to confirm John Ternus will lead all future quarterly calls, highlighting a seamless leadership transition.